CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
196 vulnerabilities with CWE-359
CVE-2024-13217
MEDIUM
Jeg Elementor Kit <2.6.11 - Info Disclosure
CVSS 4.3
CVE-2024-12041
MEDIUM
Directorist: AI-Powered WordPress Business Directory Plugin - Info ...
CVSS 5.3
CVE-2024-13216
MEDIUM
HT Event - WordPress Event Manager Plugin for Elementor <1.4.7 - In...
CVSS 4.3
CVE-2024-13215
MEDIUM
Elementor Addon Elements <1.13.10 - Info Disclosure
CVSS 4.3
CVE-2024-11396
MEDIUM
Event Monster < 1.4.3 - Unauthenticated Information Exposure via Visitors List Export
CVSS 5.3
CVE-2024-41780
MEDIUM
IBM Jazz Foundation <7.1.0 - Info Disclosure
CVSS 4.2
CVE-2024-49765
MEDIUM
Discourse - Unauthorized Account Creation via Discourse Connect Bypass
CVSS 5.3
CVE-2024-11712
MEDIUM
WP Job Portal < 2.2.3 - Unauthenticated Exposure of Private Personal Information via getResumeFileDownloadById
CVSS 5.3
CVE-2024-42494
MEDIUM
Ruijie Reyee OS <2.320 - Info Disclosure
CVSS 6.5
CVE-2024-53258
MEDIUM
Autolab 3.0.0-3.0.2 - Unauthorized Submission Download via download_all_submissions Feature
CVSS 5.3
CVE-2024-49025
MEDIUM
Microsoft Edge Chromium < 131.0.2903.48 - Exposure of Private Personal Information
CVSS 5.4
CVE-2024-11206
HIGH
com.transsion.phoenix - Info Disclosure
CVSS 7.5
CVE-2024-49386
MEDIUM
Acronis Cyber Files <9.0.0x24 - Info Disclosure
CVSS 5.7
CVE-2024-47087
MEDIUM
Apex Softcell LD Geo - Info Disclosure
CVSS 6.5
CVE-2024-47085
MEDIUM
Apex Softcell LD DP Back Office - Info Disclosure
CVSS 6.5
CVE-2024-46979
MEDIUM
XWiki 13.2-14.10.20 Unauthorized Access via NotificationFilterPreferenceLivetableResults
CVSS 5.3
CVE-2024-8891
MEDIUM
CIRCUTOR Q-SMT <1.0.4 - Info Disclosure
CVSS 5.3
CVE-2024-45787
MEDIUM
Reedos aiM-Star 2.0.1 - Authenticated Sensitive Information Exposure via API Request Interception
CVSS 6.5
CVE-2024-45591
MEDIUM
XWiki 1.8-15.10.8 - Unauthenticated Exposure of Private Personal Information via REST API
CVSS 5.3
CVE-2024-44113
MEDIUM
SAP Business Warehouse - Info Disclosure
CVSS 4.3
CVE-2024-41729
MEDIUM
SAP NetWeaver BW (BEx Analyzer) - Authenticated Information Disclosure via Missing Authorization Checks
CVSS 4.3
CVE-2024-37136
MEDIUM
Dell Path to PowerProtect <1.2 - Info Disclosure
CVSS 6.8
CVE-2024-6053
MEDIUM
TeamViewer <15.57 - Info Disclosure
CVSS 4.3
CVE-2024-7697
HIGH
Transsion Carlcare - Exposure of Private Personal Information
CVSS 7.5
CVE-2024-42347
HIGH
matrix-react-sdk <3.105.0 - Info Disclosure
CVSS 7.7
Details
Vulnerabilities
196