CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
184 vulnerabilities with CWE-359
CVE-2023-28303
LOW
Microsoft Snip & Sketch/Snipping Tool - Unauthorized Exposure of Private Personal Information
CVSS 3.3
CVE-2023-2703
HIGH
Finex Media Competition Management System < 23.07 - Exposure of Private Personal Information
CVSS 7.5
CVE-2023-22918
MEDIUM
Zyxel ATP/NWA/USG/WAX - Info Disclosure
CVSS 6.5
CVE-2023-2239
MEDIUM
microweber/microweber <1.3.4 - Info Disclosure
CVSS 6.5
CVE-2023-29203
LOW
XWiki 13.9-13.10.8 - Unauthorized Exposure of Private User Information via uorgsuggest.vm
CVSS 3.7
CVE-2023-25819
MEDIUM
Discourse tests-passed and beta branches >= 3.1.0.beta2 - Exposure of Private Personal Information via Metadata
CVSS 5.3
CVE-2023-26041
LOW
Nextcloud Talk <15.0.3 - Info Disclosure
CVSS 2.6
CVE-2022-46168
LOW
Discourse <2.8.14, <2.9.0.beta15 - Info Disclosure
CVSS 3.5
CVE-2022-41971
MEDIUM
Nextcloud Talk 12.0.0-12.2.7 - Unauthorized Video Stream Access After Removal
CVSS 4.8
CVE-2022-41936
MEDIUM
XWiki 8.1-13.10.7 - Unauthorized Exposure of Private Information via Modifications REST Endpoint
CVSS 5.3
CVE-2022-20942
MEDIUM
Cisco AsyncOS < 14.2.1-015 - Authenticated Sensitive Information Exposure via Weak Authorization Checks
CVSS 6.5
CVE-2022-2720
MEDIUM
Octopus Server 3.16.4-2022.1.3154 - Sensitive Value Exposure via Partial Masking Bypass
CVSS 5.3
CVE-2022-36091
HIGH
XWiki Platform <14.2 - Info Disclosure
CVSS 7.5
CVE-2022-0852
MEDIUM
convert2rhel < 0.26 - Unauthorized Password Exposure via Command Line
CVSS 5.5
CVE-2022-2921
HIGH
notrinoserp < 0.7 - Unauthenticated Exposure of Private Personal Information
CVSS 8.8
CVE-2022-35932
LOW
Nextcloud Talk <12.2.7, 13.0.7, 14.0.3 - Info Disclosure
CVSS 3.5
CVE-2022-24890
LOW
Nextcloud Talk < 13.0.5 - Unauthorized Exposure of Private Personal Information via Call Moderator Permissions
CVSS 2.4
CVE-2022-1365
MEDIUM
cross-fetch < 3.1.5 - Exposure of Private Personal Information
CVSS 6.5
CVE-2022-24820
MEDIUM
XWiki Platform < 12.10.11 - Unauthenticated Exposure of Private Personal Information via Velocity Document Rendering
CVSS 5.3
CVE-2022-24819
MEDIUM
XWiki < 12.10.11 - Unauthenticated Exposure of Private User Documents
CVSS 5.3
CVE-2022-0482
CRITICAL
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
CVSS 9.1
CVE-2022-24719
LOW
Fluture-Node 4.0.0/1 - Info Disclosure
CVSS 2.6
CVE-2022-0155
MEDIUM
follow-redirects < 1.14.7 - Exposure of Private Personal Information to an Unauthorized Actor
CVSS 6.5
CVE-2021-46687
MEDIUM
JFrog Artifactory <7.31.10,6.23.38 - Info Disclosure
CVSS 4.9
CVE-2021-36723
MEDIUM
Emuse eServices/eNvoice - Unauthenticated Exposure of Private Personal Information via Predictable IDs
CVSS 6.1
Details
Vulnerabilities
184