CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

174 vulnerabilities with CWE-359
CVE-2023-50053 HIGH
Foundation.app Foundation platform 1.0 - Info Disclosure
CVSS 7.6
CVE-2023-6695 MEDIUM
Beaver Themer <1.4.9 - Info Disclosure
CVSS 6.5
CVE-2023-48680 MEDIUM
Acronis Cyber Protect <16 - Info Disclosure
CVSS 5.5
CVE-2023-7014 MEDIUM
Amitzy Molongui Authorship < 4.7.5 - Exposure to Wrong Actor
CVSS 5.3
CVE-2023-6630 MEDIUM
Contact Form 7 - Insecure Direct Object Reference
CVSS 4.3
CVE-2023-42830 LOW
Apple Ipados < 16.4 - Denial of Service
CVSS 3.3
CVE-2023-50719 HIGH
Xwiki < 14.10.5 - Information Disclosure
CVSS 7.5
CVE-2023-25632 MEDIUM
Android Mobile Whale <3.0.1.2 - Auth Bypass
CVSS 5.5
CVE-2023-5983 HIGH
Botanik Software Pharmacy Automation <2.1.133.0 - Info Disclosure
CVSS 7.5
CVE-2023-36052 HIGH
Azure CLI - Info Disclosure
CVSS 8.6
CVE-2023-36018 HIGH
Visual Studio Code Jupyter Extension - SSRF
CVSS 7.8
CVE-2023-34085 LOW
AWS DynamoDB - Info Disclosure
CVSS 2.6
CVE-2023-44213 MEDIUM
Acronis Agent < c23.06 - Information Disclosure
CVSS 5.5
CVE-2023-44156 HIGH
Acronis Cyber Protect < 15 - Information Disclosure
CVSS 7.5
CVE-2023-1936 LOW
GitLab CE/EE <15.11.10/<16.0.6/<16.1.1 - Info Disclosure
CVSS 3.5
CVE-2023-35151 HIGH
Xwiki < 14.4.8 - Exposure to Wrong Actor
CVSS 7.5
CVE-2023-28303 LOW
Microsoft Snip & Sketch < 10.2008.3001.0 - Information Disclosure
CVSS 3.3
CVE-2023-2703 HIGH
Finexmedia Competition Management System - Exposure to Wrong Actor
CVSS 7.5
CVE-2023-22918 MEDIUM
Zyxel ATP/NWA/USG/WAX - Info Disclosure
CVSS 6.5
CVE-2023-2239 MEDIUM
microweber/microweber <1.3.4 - Info Disclosure
CVSS 6.5
CVE-2023-29203 LOW
XWiki - Info Disclosure
CVSS 3.7
CVE-2023-25819 MEDIUM
Discourse < 3.1.0 - Information Disclosure
CVSS 5.3
CVE-2023-26041 LOW
Nextcloud Talk <15.0.3 - Info Disclosure
CVSS 2.6
CVE-2022-46168 LOW
Discourse <2.8.14, <2.9.0.beta15 - Info Disclosure
CVSS 3.5
CVE-2022-41971 MEDIUM
Nextcloud Talk < 12.2.8 - Information Disclosure
CVSS 4.8
Details
Vulnerabilities 174