CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
196 vulnerabilities with CWE-359
CVE-2023-42830
LOW
iPadOS < 16.4 - Unauthorized Access to Sensitive Location Information via Log Entries
CVSS 3.3
CVE-2023-50719
HIGH
XWiki Platform 7.2-milestone-2-14.10.14 - Unauthenticated Exposure of Sensitive Information via Solr Search
CVSS 7.5
CVE-2023-25632
MEDIUM
Android Mobile Whale <3.0.1.2 - Auth Bypass
CVSS 5.5
CVE-2023-5983
HIGH
Botanik Software Pharmacy Automation <2.1.133.0 - Info Disclosure
CVSS 7.5
CVE-2023-36052
HIGH
Azure Command-Line Interface < 2.53.1 - Exposure of Private Personal Information via REST Command
CVSS 8.6
CVE-2023-36018
HIGH
Visual Studio Code Jupyter Extension - SSRF
CVSS 7.8
CVE-2023-34085
LOW
PingFederate < 11.3.0 - Unauthorized Exposure of Private User Attributes via DynamoDB Request
CVSS 2.6
CVE-2023-44213
MEDIUM
Acronis Agent < c23.06 - Sensitive Information Disclosure via Excessive System Information Collection
CVSS 5.5
CVE-2023-44156
HIGH
Acronis Cyber Protect 15 < build 35979 - Sensitive Information Disclosure via Spell-Jacking
CVSS 7.5
CVE-2023-1936
LOW
GitLab CE/EE <15.11.10/<16.0.6/<16.1.1 - Info Disclosure
CVSS 3.5
CVE-2023-35151
HIGH
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
CVSS 7.5
CVE-2023-28303
LOW
Microsoft Snip & Sketch/Snipping Tool - Unauthorized Exposure of Private Personal Information
CVSS 3.3
CVE-2023-2703
HIGH
Finex Media Competition Management System < 23.07 - Exposure of Private Personal Information
CVSS 7.5
CVE-2023-22918
MEDIUM
Zyxel ATP/NWA/USG/WAX - Info Disclosure
CVSS 6.5
CVE-2023-2239
MEDIUM
microweber/microweber <1.3.4 - Info Disclosure
CVSS 6.5
CVE-2023-29203
LOW
XWiki 13.9-13.10.8 - Unauthorized Exposure of Private User Information via uorgsuggest.vm
CVSS 3.7
CVE-2023-25819
MEDIUM
Discourse tests-passed and beta branches >= 3.1.0.beta2 - Exposure of Private Personal Information via Metadata
CVSS 5.3
CVE-2023-26041
LOW
Nextcloud Talk <15.0.3 - Info Disclosure
CVSS 2.6
CVE-2022-46168
LOW
Discourse <2.8.14, <2.9.0.beta15 - Info Disclosure
CVSS 3.5
CVE-2022-41971
MEDIUM
Nextcloud Talk 12.0.0-12.2.7 - Unauthorized Video Stream Access After Removal
CVSS 4.8
CVE-2022-41936
MEDIUM
XWiki 8.1-13.10.7 - Unauthorized Exposure of Private Information via Modifications REST Endpoint
CVSS 5.3
CVE-2022-20942
MEDIUM
Cisco AsyncOS < 14.2.1-015 - Authenticated Sensitive Information Exposure via Weak Authorization Checks
CVSS 6.5
CVE-2022-2720
MEDIUM
Octopus Server 3.16.4-2022.1.3154 - Sensitive Value Exposure via Partial Masking Bypass
CVSS 5.3
CVE-2022-36091
HIGH
XWiki Platform <14.2 - Info Disclosure
CVSS 7.5
CVE-2022-0852
MEDIUM
convert2rhel < 0.26 - Unauthorized Password Exposure via Command Line
CVSS 5.5
Details
Vulnerabilities
196