CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

367 vulnerabilities with CWE-497
CVE-2026-25325 MEDIUM
rtMedia for WordPress, BuddyPress and bbPress <= 4.7.8 - Sensitive Data Exposure
CVSS 5.3
CVE-2026-25023 MEDIUM
ContestsWP <2.0.7 - Info Disclosure
CVSS 5.3
CVE-2026-24998 MEDIUM
WPMU DEV - Your All-in-One WordPress Platform Hustle <7.8.9.2 - Inf...
CVSS 5.3
CVE-2026-24593 MEDIUM
Strategy11 Team AWP Classifieds <4.4.3 - Info Disclosure
CVSS 5.3
CVE-2026-24553 MEDIUM
Dotstore Fraud Prevention For Woocommerce <2.3.1 - Info Disclosure
CVSS 4.3
CVE-2026-24536 MEDIUM
Webpushr <= 4.38.0 - Sensitive Data Exposure via Embedded Data Retrieval
CVSS 5.3
CVE-2026-24523 MEDIUM
Marcus WP FullCalendar <1.7 - Info Disclosure
CVSS 5.3
CVE-2026-24377 MEDIUM
POSIMYTH Nexter Blocks <4.6.3 - Info Disclosure
CVSS 4.3
CVE-2026-22915 MEDIUM
Product <Version> - Info Disclosure
CVSS 4.3
CVE-2026-0887 MEDIUM
Firefox and Thunderbird < 140.7.0 and < 147.0 - Information Disclosure in PDF Viewer
CVSS 4.3
CVE-2026-0494 MEDIUM
SAP Fiori App (Intercompany Balance Reconciliation) - Exposure of Sensitive System Information
CVSS 4.3
CVE-2026-0853 MEDIUM
A-Plus Video Technologies - Info Disclosure
CVSS 5.3
CVE-2026-22537 MEDIUM
EFACEC QC 60/90/120 - Exposure of Sensitive System Information via Unhardened System Files
CVE-2025-59178 MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability
CVE-2025-15623 HIGH
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
CVSS 7.5
CVE-2025-36373 MEDIUM
Incorrect administrative access control in IBM DataPower Gateway
CVSS 4.1
CVE-2025-41763 MEDIUM
universal_bacnet_router_firmware < 6.0.1.0 - Unauthorized Sensitive Information Exposure via wwwdnload.cgi Endpoint
CVSS 6.5
CVE-2025-13616 MEDIUM
IBM DataStage on Cloud Pak 5.1.2-5.3.0 - Info Disclosure
CVSS 6.5
CVE-2025-47378 HIGH
Shared VM Reference - Info Disclosure
CVSS 7.1
CVE-2025-13691 HIGH
IBM DataStage 5.1.2-5.3.0 - Info Disclosure
CVSS 8.1
CVE-2025-9986 HIGH
Vadi Corporate Information Systems Ltd. Co. DIGIKENT <13092025 - In...
CVSS 8.2
CVE-2025-13651 HIGH
Microcom ZeusWeb <6.1.31 - Info Disclosure
CVSS 7.5
CVE-2025-66599 MEDIUM
FAST/TOOLS <10.04 - Info Disclosure
CVE-2025-14150 MEDIUM
IBM webMethods Integration <11.1 - Info Disclosure
CVSS 6.5
CVE-2025-27550 LOW
IBM Jazz Reporting Service - Info Disclosure
CVSS 3.5
Details
Vulnerabilities 367