CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

174 vulnerabilities with CWE-359
CVE-2022-41936 MEDIUM
XWiki Platform - Info Disclosure
CVSS 5.3
CVE-2022-20942 MEDIUM
Cisco Asyncos < 14.2.1-015 - Incorrect Authorization
CVSS 6.5
CVE-2022-2720 MEDIUM
Octopus Server - Info Disclosure
CVSS 5.3
CVE-2022-36091 HIGH
XWiki Platform <14.2 - Info Disclosure
CVSS 7.5
CVE-2022-0852 MEDIUM
Convert2rhel < 0.26 - Exposure to Wrong Actor
CVSS 5.5
CVE-2022-2921 HIGH
Notrinoserp < 0.7 - Privilege Escalation
CVSS 8.8
CVE-2022-35932 LOW
Nextcloud Talk <12.2.7, 13.0.7, 14.0.3 - Info Disclosure
CVSS 3.5
CVE-2022-24890 LOW
Nextcloud Talk < 13.0.5 - Information Disclosure
CVSS 2.4
CVE-2022-1365 MEDIUM
Cross-fetch < 3.1.5 - Incorrect Authorization
CVSS 6.5
CVE-2022-24820 MEDIUM
Xwiki < 12.10.11 - Missing Authentication
CVSS 5.3
CVE-2022-24819 MEDIUM
XWiki Platform - Info Disclosure
CVSS 5.3
CVE-2022-0482 CRITICAL
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
CVSS 9.1
CVE-2022-24719 LOW
Fluture-Node 4.0.0/1 - Info Disclosure
CVSS 2.6
CVE-2022-0155 MEDIUM
follow-redirects - Info Disclosure
CVSS 6.5
CVE-2021-46687 MEDIUM
JFrog Artifactory <7.31.10,6.23.38 - Info Disclosure
CVSS 4.9
CVE-2021-36723 MEDIUM
Emuse - Eservices / Envoice - Information Disclosure
CVSS 6.1
CVE-2021-3980 HIGH
elgg - Info Disclosure
CVSS 7.5
CVE-2021-28559 MEDIUM
Acrobat Reader DC <2021.001.20150 - Info Disclosure
CVSS 5.3
CVE-2021-21823 HIGH
Komoot < 11.1.11 - Information Disclosure
CVSS 7.5
CVE-2021-22876 MEDIUM
curl <7.75.0 - Info Disclosure
CVSS 5.3
CVE-2020-37173 HIGH
AVideo Platform 8.1 - Info Disclosure
CVSS 7.5
CVE-2020-1688 MEDIUM
Juniper Networks SRX Series/NFX Series - Privilege Escalation
CVSS 6.5
CVE-2019-15623 MEDIUM
Nextcloud Server 16.0.1 - Info Disclosure
CVSS 5.3
CVE-2017-16769 MEDIUM
Synology Photo Station <6.8.1-3458 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 174