CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

311 vulnerabilities with CWE-497
CVE-2025-49914 MEDIUM
MotoPress mp-restaurant-menu <2.4.7 - Info Disclosure
CVSS 6.5
CVE-2025-47319 MEDIUM
Qualcomm Sm6650p Firmware - Information Disclosure
CVSS 6.7
CVE-2025-34442 HIGH
AVideo <20.1 - Info Disclosure
CVSS 7.5
CVE-2025-67948 MEDIUM
SendPulse Email Marketing Newsletter <= 2.2.1 - Info Disclosure
CVSS 4.3
CVE-2025-14712 HIGH
Student Learning Assessment and Support System - Info Disclosure
CVSS 7.5
CVE-2025-43471 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.5
CVE-2025-43406 MEDIUM
macOS Tahoe 26.1 - Info Disclosure
CVSS 5.5
CVE-2025-67717 MEDIUM
Zitadel < 2.71.19 - Information Disclosure
CVSS 4.3
CVE-2025-67567 MEDIUM
uixthemes Sober <3.5.11 - Info Disclosure
CVSS 5.3
CVE-2025-67565 MEDIUM
Sizam Rehub <20 - Info Disclosure
CVSS 5.3
CVE-2025-67564 MEDIUM
alekv Pixel Manager for WooCommerce <= 1.51.1 - Info Disclosure
CVSS 5.3
CVE-2025-67470 MEDIUM
Essential Plugin Portfolio and Projects <1.5.5 - Info Disclosure
CVSS 4.3
CVE-2025-63070 MEDIUM
Shahjada Download Manager <4.0 - Info Disclosure
CVSS 4.3
CVE-2025-63058 MEDIUM
Hiroaki Miyashita Custom Field Template <= 2.7.4 - Info Disclosure
CVSS 4.3
CVE-2025-63013 MEDIUM
ThimPress WP Hotel Booking <2.2.8 - Info Disclosure
CVSS 4.3
CVE-2025-63009 MEDIUM
yuvalo WP Google Analytics Events <2.8.3 - Info Disclosure
CVSS 5.3
CVE-2025-62737 MEDIUM
opicron Image Cleanup <1.9.3 - Info Disclosure
CVSS 5.3
CVE-2025-62735 MEDIUM
Joel User Spam Remover <1.1 - Info Disclosure
CVSS 5.3
CVE-2025-64061 MEDIUM
Primakon Pi Portal 1.0.18 - Info Disclosure
CVSS 4.3
CVE-2025-36112 MEDIUM
IBM Sterling B2B Integrator & File Gateway <6.2.1.1 - Info Disclosure
CVSS 5.3
CVE-2025-66059 MEDIUM
Seriously Simple Podcasting <3.13.0 - Info Disclosure
CVSS 5.3
CVE-2025-66056 MEDIUM
Uncanny Automator <6.10.0 - Info Disclosure
CVSS 4.3
CVE-2025-36160 MEDIUM
IBM Concert <2.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-13160 MEDIUM
IQ-Support - Info Disclosure
CVSS 5.3
CVE-2025-64267 MEDIUM
WPSwings WooCommerce Ultimate Points And Rewards <2.10.3 - Info Dis...
CVSS 4.3
Details
Vulnerabilities 311