CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

367 vulnerabilities with CWE-497
CVE-2025-67546 MEDIUM
weDevs WP ERP <1.16.6 - Info Disclosure
CVSS 6.5
CVE-2025-64272 MEDIUM
GetResponse Email marketing <1.5.3 - Info Disclosure
CVSS 6.5
CVE-2025-64270 MEDIUM
Masteriyo LMS <2.0.3 - Info Disclosure
CVSS 6.5
CVE-2025-64258 HIGH
wpweb Follow My Blog Post <= 2.3.9 - Info Disclosure
CVSS 7.5
CVE-2025-49914 MEDIUM
MotoPress mp-restaurant-menu <2.4.7 - Info Disclosure
CVSS 6.5
CVE-2025-47319 MEDIUM
Qualcomm Firmware - Exposure of Sensitive System Information via TA-to-TA Communication APIs
CVSS 6.7
CVE-2025-34442 HIGH
AVideo < 20.1 - Sensitive System Information Exposure via Public API Endpoints
CVSS 7.5
CVE-2025-67948 MEDIUM
SendPulse Email Marketing Newsletter <= 2.2.1 - Info Disclosure
CVSS 4.3
CVE-2025-14712 HIGH
Student Learning Assessment and Support System - Info Disclosure
CVSS 7.5
CVE-2025-43471 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.5
CVE-2025-43406 MEDIUM
macOS < 26.1 - Unprotected User Data Exposure via Logic Issue
CVSS 5.5
CVE-2025-67717 MEDIUM
ZITADEL 2.44.0-3.4.4 and 4.0.0-rc.1-4.7.1 - Authenticated Sensitive Information Disclosure via Total User Count
CVSS 4.3
CVE-2025-67567 MEDIUM
uixthemes Sober <3.5.11 - Info Disclosure
CVSS 5.3
CVE-2025-67565 MEDIUM
Rehub <= 19.9.9.1 - Sensitive Data Exposure via Embedded Data Retrieval
CVSS 5.3
CVE-2025-67564 MEDIUM
alekv Pixel Manager for WooCommerce <= 1.51.1 - Info Disclosure
CVSS 5.3
CVE-2025-67470 MEDIUM
Essential Plugin Portfolio and Projects <1.5.5 - Info Disclosure
CVSS 4.3
CVE-2025-63070 MEDIUM
Shahjada Download Manager <4.0 - Info Disclosure
CVSS 4.3
CVE-2025-63058 MEDIUM
Hiroaki Miyashita Custom Field Template <= 2.7.4 - Info Disclosure
CVSS 4.3
CVE-2025-63013 MEDIUM
ThimPress WP Hotel Booking <2.2.8 - Info Disclosure
CVSS 4.3
CVE-2025-63009 MEDIUM
yuvalo WP Google Analytics Events <2.8.3 - Info Disclosure
CVSS 5.3
CVE-2025-62737 MEDIUM
opicron Image Cleanup <1.9.3 - Info Disclosure
CVSS 5.3
CVE-2025-62735 MEDIUM
Joel User Spam Remover <1.1 - Info Disclosure
CVSS 5.3
CVE-2025-64061 MEDIUM
Primakon Pi Portal 1.0.18 - Info Disclosure
CVSS 4.3
CVE-2025-36112 MEDIUM
IBM Sterling B2B Integrator & File Gateway <6.2.1.1 - Info Disclosure
CVSS 5.3
CVE-2025-66059 MEDIUM
Seriously Simple Podcasting <3.13.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 367