CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

289 vulnerabilities with CWE-497
CVE-2025-41763 MEDIUM
wwwdnload.cgi - Info Disclosure
CVSS 6.5
CVE-2025-13616 MEDIUM
IBM DataStage on Cloud Pak 5.1.2-5.3.0 - Info Disclosure
CVSS 6.5
CVE-2025-47378 HIGH
Shared VM Reference - Info Disclosure
CVSS 7.1
CVE-2026-27494 CRITICAL
n8n <2.10.1/2.9.3/1.123.22 - Authenticated RCE
CVSS 9.9
CVE-2026-24314 MEDIUM
SAP S/4HANA - Info Disclosure
CVSS 4.3
CVE-2026-3075 MEDIUM
Simple Ajax Chat <=20251121 - Info Disclosure
CVSS 5.3
CVE-2026-25389 MEDIUM
EventPrime <=4.2.8.3 - Info Disclosure
CVSS 5.3
CVE-2026-25325 MEDIUM
rtMedia <=4.7.8 - Info Disclosure
CVSS 5.3
CVE-2025-13691 HIGH
IBM DataStage 5.1.2-5.3.0 - Info Disclosure
CVSS 8.1
CVE-2025-9986 HIGH
Vadi Corporate Information Systems Ltd. Co. DIGIKENT <13092025 - In...
CVSS 8.2
CVE-2025-13651
Microcom ZeusWeb <6.1.31 - Info Disclosure
CVE-2025-66599
FAST/TOOLS <10.04 - Info Disclosure
CVE-2025-14150 MEDIUM
IBM webMethods Integration <11.1 - Info Disclosure
CVSS 6.5
CVE-2025-27550 LOW
IBM Jazz Reporting Service - Info Disclosure
CVSS 3.5
CVE-2026-25023 MEDIUM
ContestsWP <2.0.7 - Info Disclosure
CVSS 5.3
CVE-2026-24998 MEDIUM
WPMU DEV - Your All-in-One WordPress Platform Hustle <7.8.9.2 - Inf...
CVSS 5.3
CVE-2025-36238 MEDIUM
IBM PowerVM Hypervisor - Info Disclosure
CVSS 6.0
CVE-2023-37525 MEDIUM
Hcltech Bigfix Compliance - Information Disclosure
CVSS 5.3
CVE-2025-59098
Access Manager - Info Disclosure
CVE-2026-24593 MEDIUM
Strategy11 Team AWP Classifieds <4.4.3 - Info Disclosure
CVSS 5.3
CVE-2026-24553 MEDIUM
Dotstore Fraud Prevention For Woocommerce <2.3.1 - Info Disclosure
CVSS 4.3
CVE-2026-24536 HIGH
Webpushr <4.38.0 - Info Disclosure
CVSS 7.5
CVE-2026-24523 HIGH
Marcus WP FullCalendar <1.7 - Info Disclosure
CVSS 7.5
CVE-2026-24377 HIGH
POSIMYTH Nexter Blocks <4.6.3 - Info Disclosure
CVSS 7.5
CVE-2025-68046 MEDIUM
ThemeHunk Contact Form & Lead Form Elementor Builder <2.0.1 - Info ...
CVSS 6.5
Details
Vulnerabilities 289