CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

368 vulnerabilities with CWE-497
CVE-2025-32251 MEDIUM
J. Tyler Wiest Jetpack Feedback Exporter <1.23 - Info Disclosure
CVSS 5.3
CVE-2025-0278 MEDIUM
HCL Traveler < 14.0.0.1 - Internal Path Disclosure in Windows Application
CVSS 4.3
CVE-2025-31832 MEDIUM
Beee ACF City Selector <1.16.0 - Info Disclosure
CVSS 5.3
CVE-2025-30802 MEDIUM
WPBean Our Team Members <= 2.2 - Sensitive System Information Exposure
CVSS 4.3
CVE-2025-27149 LOW
zulip_server < 10.0 - Unauthorized Sensitive Data Exposure via Data Export Feature
CVSS 2.7
CVE-2025-2598 MEDIUM
AWS Cloud Development Kit 2.172.0-2.178.2 - Exposure of Sensitive System Information via Credential Plugin
CVSS 5.5
CVE-2025-23382 MEDIUM
Dell Secure Connect Gateway (SCG) 5.0 Appliance - Info Disclosure
CVSS 5.5
CVE-2025-26911 MEDIUM
Bowo System Dashboard <2.8.18 - Info Disclosure
CVSS 4.3
CVE-2025-26758 MEDIUM
RebelCode Spotlight Social Media Feeds <1.7.1 - Info Disclosure
CVSS 5.3
CVE-2025-1212 MEDIUM
GitLab CE/EE <17.6.5-17.8.2 - Info Disclosure
CVSS 4.3
CVE-2025-1144 CRITICAL
School Affairs System - Info Disclosure
CVSS 9.8
CVE-2025-22222 HIGH
VMware Aria Operations - Info Disclosure
CVSS 7.7
CVE-2025-0061 HIGH
SAP BusinessObjects - Info Disclosure
CVSS 8.7
CVE-2025-0059 MEDIUM
SAP NetWeaver Application Server ABAP - Exposure of Sensitive System Information via Local Browser Storage
CVSS 6.0
CVE-2025-0056 MEDIUM
SAP GUI for Java >= BC-FES-JAV 7.80 < BC-FES-JAV 7.80 - Exposure of Sensitive System Information
CVSS 6.0
CVE-2025-0055 MEDIUM
SAP GUI for Windows - Info Disclosure
CVSS 6.0
CVE-2024-58320 MEDIUM
Kentico Xperience < 13.0.159 - Unauthenticated Sensitive Information Exposure via Public Endpoint
CVSS 5.3
CVE-2024-13998 MEDIUM
Nagios XI <2024R1.1.3 - Info Disclosure
CVSS 6.5
CVE-2024-13999 CRITICAL
Nagios XI <2024R1.1.3 - Info Disclosure
CVSS 9.8
CVE-2024-13995 HIGH
Nagios XI <2024R1.1.2 - Info Disclosure
CVSS 8.8
CVE-2024-12367 HIGH
Vegagrup Software Vega Master <20250916 - Info Disclosure
CVSS 8.6
CVE-2024-51770 HIGH
HPE AutoPass License Server <9.17 - Info Disclosure
CVSS 7.5
CVE-2024-45549 HIGH
Qualcomm Snapdragon and SM Series Firmware - Information Disclosure in MQ Channel Creation
CVSS 7.7
CVE-2024-8313 HIGH
B&R APROL <4.4-00P5 - Info Disclosure
CVE-2024-10940 MEDIUM
Langchain-core <0.1.53,<0.2.43,<0.3.15 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 368