CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

367 vulnerabilities with CWE-497
CVE-2025-36238 MEDIUM
IBM PowerVM Hypervisor - Info Disclosure
CVSS 6.0
CVE-2025-59098 HIGH
dormakaba Access Manager 92xx-k5/k7 - Unauthenticated Sensitive Information Exposure via TCP Socket
CVE-2025-68046 MEDIUM
ThemeHunk Contact Form & Lead Form Elementor Builder <2.0.1 - Info ...
CVSS 6.5
CVE-2025-67954 MEDIUM
Dimitri Grassi Salon booking system <10.30.3 - Info Disclosure
CVSS 6.5
CVE-2025-63051 MEDIUM
REHub Framework <19.9.9.4 - Info Disclosure
CVSS 4.3
CVE-2025-55131 HIGH
Node.js 4.0-25.2.0 - Uninitialized Memory Exposure via Buffer Allocation Interruption
CVSS 7.1
CVE-2025-31051 MEDIUM
EngoTheme Plant - Gardening & Houseplants <1.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-34171 MEDIUM
CasaOS <= 0.4.15 - Unauthenticated Sensitive Information Exposure via Image and Debug Endpoints
CVSS 5.3
CVE-2025-9110 HIGH
QNAP QTS and QuTS hero - Exposure of Sensitive System Information
CVSS 7.5
CVE-2025-62083 MEDIUM
WP Messiah BoomDevs WordPress Coming Soon Plugin <1.0.4 - Info Disc...
CVSS 4.3
CVE-2025-49340 MEDIUM
Digages Direct Payments WP - Info Disclosure
CVSS 4.3
CVE-2025-62143 MEDIUM
nicashmu Post Video Players <1.163 - Info Disclosure
CVSS 4.3
CVE-2025-62114 MEDIUM
Marcelo Torres Download Media Library <0.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-69026 MEDIUM
Roxnor PopupKit <2.1.5 - Info Disclosure
CVSS 4.3
CVE-2025-69025 MEDIUM
Poptics <= 1.0.20 - Sensitive Data Exposure
CVSS 4.3
CVE-2025-68988 MEDIUM
o2oe E-Invoice App Malaysia <1.1.0 - Info Disclosure
CVSS 5.3
CVE-2025-36229 LOW
IBM Aspera Faspex <5.0.14.1 - Info Disclosure
CVSS 3.1
CVE-2025-68943 MEDIUM
Gitea < 1.21.8 - Unauthorized Exposure of User Login Times via Explore Users Sort Order
CVSS 5.3
CVE-2025-68606 MEDIUM
WPXPO PostX <5.0.3 - Info Disclosure
CVSS 5.3
CVE-2025-68576 MEDIUM
Virusdie <= 1.1.6 - Exposure of Sensitive System Information
CVSS 4.3
CVE-2025-68494 MEDIUM
Leap13 Premium Addons for Elementor <4.11.53 - Info Disclosure
CVSS 5.3
CVE-2025-67621 MEDIUM
8 Day Week Print Workflow <1.2.6 - Info Disclosure
CVSS 4.3
CVE-2025-68551 MEDIUM
Vikas Ratudi VPSUForm <3.2.24 - Info Disclosure
CVSS 6.5
CVE-2025-11545 CRITICAL
Sharp Display Solutions - Info Disclosure
CVE-2025-62955 MEDIUM
HappyDevs TempTool <1.3.1 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 367