CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

196 vulnerabilities with CWE-359
CVE-2022-2921 HIGH
notrinoserp < 0.7 - Unauthenticated Exposure of Private Personal Information
CVSS 8.8
CVE-2022-35932 LOW
Nextcloud Talk <12.2.7, 13.0.7, 14.0.3 - Info Disclosure
CVSS 3.5
CVE-2022-24890 LOW
Nextcloud Talk < 13.0.5 - Unauthorized Exposure of Private Personal Information via Call Moderator Permissions
CVSS 2.4
CVE-2022-1365 MEDIUM
cross-fetch < 3.1.5 - Exposure of Private Personal Information
CVSS 6.5
CVE-2022-24820 MEDIUM
XWiki Platform < 12.10.11 - Unauthenticated Exposure of Private Personal Information via Velocity Document Rendering
CVSS 5.3
CVE-2022-24819 MEDIUM
XWiki < 12.10.11 - Unauthenticated Exposure of Private User Documents
CVSS 5.3
CVE-2022-0482 CRITICAL
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
CVSS 9.1
CVE-2022-24719 LOW
Fluture-Node 4.0.0/1 - Info Disclosure
CVSS 2.6
CVE-2022-0155 MEDIUM
follow-redirects < 1.14.7 - Exposure of Private Personal Information to an Unauthorized Actor
CVSS 6.5
CVE-2021-46687 MEDIUM
JFrog Artifactory <7.31.10,6.23.38 - Info Disclosure
CVSS 4.9
CVE-2021-36723 MEDIUM
Emuse eServices/eNvoice - Unauthenticated Exposure of Private Personal Information via Predictable IDs
CVSS 6.1
CVE-2021-3980 HIGH
Elgg < 3.3.23 - Exposure of Private Personal Information
CVSS 7.5
CVE-2021-28559 MEDIUM
Acrobat Reader DC <2021.001.20150 - Info Disclosure
CVSS 5.3
CVE-2021-21823 HIGH
komoot 10.26.9-11.1.11 - Information Disclosure via Friend Finder
CVSS 7.5
CVE-2021-22876 MEDIUM
libcurl 7.1.1-7.75.0 - Credential Leak via HTTP Referer Header
CVSS 5.3
CVE-2020-25900 MEDIUM
HelloTalk < 3.4.1 - Exposure of Private Personal Information to an Unauthorized Actor
CVSS 5.3
CVE-2020-37173 HIGH
AVideo Platform 8.1 - Info Disclosure
CVSS 7.5
CVE-2020-1688 MEDIUM
Juniper Networks SRX Series/NFX Series - Privilege Escalation
CVSS 6.5
CVE-2019-25762 HIGH
Joomla! Component JoomProject 1.1.3.2 Information Disclosure
CVSS 7.5
CVE-2019-15623 MEDIUM
Nextcloud Server 16.0.1 - Info Disclosure
CVSS 5.3
CVE-2017-16769 MEDIUM
Synology Photo Station <6.8.1-3458 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 196