CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

184 vulnerabilities with CWE-359
CVE-2024-29987 MEDIUM
Microsoft Edge Chromium < 124.0.2478.51 - Information Disclosure
CVSS 6.5
CVE-2024-29986 MEDIUM
Microsoft Edge Chromium for Android < 124.0.2478.51 - Exposure of Private Personal Information
CVSS 5.4
CVE-2024-29888 MEDIUM
Saleor 3.14.56-3.14.61 - Unauthorized Exposure of Private Personal Information via Click-and-Collect Address Overwrite
CVSS 4.2
CVE-2024-28387 HIGH
axonaut < 3.2.0 - Sensitive Information Exposure via log.txt
CVSS 7.5
CVE-2024-26192 HIGH
Microsoft Edge Chromium < 122.0.2365.52 - Information Disclosure
CVSS 8.2
CVE-2024-23211 LOW
Safari < 17.3 - Unauthorized Exposure of Private Browsing Activity
CVSS 3.3
CVE-2023-45721 MEDIUM
HCL Domino Leap 1.1-1.1.3 - Unauthenticated Exposure of Private Personal Information
CVSS 5.3
CVE-2023-45720 MEDIUM
HCL Leap < 9.3.5 - Unauthenticated Exposure of Private Personal Information via Insufficient Default Configuration
CVSS 5.3
CVE-2023-44255 MEDIUM
Fortinet FortiManager <7.4.2, FortiAnalyzer <7.4.2, FortiAnalyzer-B...
CVSS 4.1
CVE-2023-50053 HIGH
Foundation.app Foundation platform 1.0 - Info Disclosure
CVSS 7.6
CVE-2023-6695 MEDIUM
Beaver Themer <1.4.9 - Info Disclosure
CVSS 6.5
CVE-2023-48680 MEDIUM
Acronis Cyber Protect <16 - Info Disclosure
CVSS 5.5
CVE-2023-7014 MEDIUM
Molongui Authorship < 4.7.4 - Unauthenticated Sensitive Information Exposure via ma_debu Parameter
CVSS 5.3
CVE-2023-6630 MEDIUM
Contact Form 7 - Insecure Direct Object Reference
CVSS 4.3
CVE-2023-42830 LOW
iPadOS < 16.4 - Unauthorized Access to Sensitive Location Information via Log Entries
CVSS 3.3
CVE-2023-50719 HIGH
XWiki Platform 7.2-milestone-2-14.10.14 - Unauthenticated Exposure of Sensitive Information via Solr Search
CVSS 7.5
CVE-2023-25632 MEDIUM
Android Mobile Whale <3.0.1.2 - Auth Bypass
CVSS 5.5
CVE-2023-5983 HIGH
Botanik Software Pharmacy Automation <2.1.133.0 - Info Disclosure
CVSS 7.5
CVE-2023-36052 HIGH
Azure Command-Line Interface < 2.53.1 - Exposure of Private Personal Information via REST Command
CVSS 8.6
CVE-2023-36018 HIGH
Visual Studio Code Jupyter Extension - SSRF
CVSS 7.8
CVE-2023-34085 LOW
PingFederate < 11.3.0 - Unauthorized Exposure of Private User Attributes via DynamoDB Request
CVSS 2.6
CVE-2023-44213 MEDIUM
Acronis Agent < c23.06 - Sensitive Information Disclosure via Excessive System Information Collection
CVSS 5.5
CVE-2023-44156 HIGH
Acronis Cyber Protect 15 < build 35979 - Sensitive Information Disclosure via Spell-Jacking
CVSS 7.5
CVE-2023-1936 LOW
GitLab CE/EE <15.11.10/<16.0.6/<16.1.1 - Info Disclosure
CVSS 3.5
CVE-2023-35151 HIGH
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
CVSS 7.5
Details
Vulnerabilities 184