CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

368 vulnerabilities with CWE-497
CVE-2025-4364 HIGH
Fleet Management System < February 6th, 2025 - Unauthenticated Exposure of Sensitive System Information
CVE-2025-39394 MEDIUM
Solid Plugins AnalyticsWP <2.1.2 - Info Disclosure
CVSS 5.3
CVE-2025-32299 MEDIUM
Themovation QuickCal <1.0.15 - Info Disclosure
CVSS 4.3
CVE-2025-31062 MEDIUM
redqteam Wishlist <2.1.0 - Info Disclosure
CVSS 4.3
CVE-2025-48024 MEDIUM
BlueWave Checkmate <2.1 - Info Disclosure
CVSS 5.0
CVE-2025-30011 MEDIUM
SAP Supplier Relationship Management - Info Disclosure
CVSS 5.3
CVE-2025-46747 MEDIUM
User Management < unknown - Info Disclosure
CVSS 5.7
CVE-2025-46718 LOW
sudo-rs < 0.2.6 - Unauthorized Sensitive Information Exposure via -U Flag
CVSS 3.3
CVE-2025-46717 LOW
sudo-rs < 0.2.6 - Unauthorized Sensitive Information Exposure via sudo --list
CVSS 3.3
CVE-2025-3506 MEDIUM
Checkmk 2.1.0-2.3.0 and < 2.4.0b6 - Unauthenticated Exposure of Sensitive System Information
CVSS 5.3
CVE-2025-47540 MEDIUM
weDevs weMail <= 1.14.13 - Exposure of Sensitive System Information
CVSS 5.3
CVE-2025-3606 HIGH
Vestel AC Charger 3.75.0 - Info Disclosure
CVSS 7.5
CVE-2025-46421 MEDIUM
Red Hat Enterprise Linux - Unauthorized Authorization Header Exposure via HTTP Redirect
CVSS 6.8
CVE-2025-32792 HIGH
ses < 1.12.0 - Exposure of Sensitive System Information via Compartment API
CVE-2025-39439 MEDIUM
wpLike2Get <1.2.9 - Info Disclosure
CVSS 5.3
CVE-2025-39589 MEDIUM
WPDeveloper Essential Addons for Elementor <6.1.9 - Info Disclosure
CVSS 4.3
CVE-2025-39556 MEDIUM
Mediavine Control Panel <2.10.6 - Info Disclosure
CVSS 5.3
CVE-2025-26730 HIGH
NotFound Macro Calculator - Info Disclosure
CVSS 7.5
CVE-2025-30686 HIGH
Oracle Hospitality Simphony 19.1-19.7 - Unauthorized Data Access and Partial Denial of Service via EMC Component
CVSS 7.6
CVE-2025-32228 MEDIUM
WP Messiah Ai Image Alt Text Generator <1.0.8 - Info Disclosure
CVSS 4.3
CVE-2025-31003 LOW
Bogdan Bendziukov Squeeze - Info Disclosure
CVSS 2.7
CVE-2025-27934 HIGH
Wi-Fi AP UNIT AC-WPS-11ac - Info Disclosure
CVSS 7.5
CVE-2025-32164 MEDIUM
maennchen1.de m1.DownloadList - Info Disclosure
CVSS 6.5
CVE-2025-32026 LOW
Element Web <1.11.96 - Info Disclosure
CVSS 3.8
CVE-2025-32255 MEDIUM
ERA404 StaffList <3.2.6 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 368