CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

311 vulnerabilities with CWE-497
CVE-2025-58007 MEDIUM
NerdPress Social Pug <1.35.1 - Info Disclosure
CVSS 4.3
CVE-2025-57937 MEDIUM
WPeMatico RSS Feed Fetcher <2.8.10 - Info Disclosure
CVSS 4.3
CVE-2025-57916 MEDIUM
Nurul Amin WP System Information <1.5 - Info Disclosure
CVSS 4.3
CVE-2025-36146 MEDIUM
IBM Lakehouse - Info Disclosure
CVSS 4.3
CVE-2025-4235 HIGH
Palo Alto Networks User-ID Credential Agent - Info Disclosure
CVE-2025-10264 CRITICAL
NVR - Info Disclosure
CVSS 10.0
CVE-2025-6769 MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Info Disclosure
CVSS 4.3
CVE-2025-9364 HIGH
Redis - Info Disclosure
CVSS 8.8
CVE-2025-58866 LOW
Rami Yushuvaev Site Info <1.1 - Info Disclosure
CVSS 2.7
CVE-2025-58797 MEDIUM
Ninja Charts <3.3.2 - Info Disclosure
CVSS 5.3
CVE-2025-2667 LOW
IBM Sterling B2B Integrator <6.2.0.5 - Info Disclosure
CVSS 2.7
CVE-2025-36162 MEDIUM
IBM DevOps Deploy/UCD <8.1.2.2 - Info Disclosure
CVSS 4.3
CVE-2025-8700 MEDIUM
Invoice Ninja - Privilege Escalation
CVE-2025-8597 MEDIUM
MacVim - Privilege Escalation
CVE-2025-57888 MEDIUM
NooTheme Jobmonster <4.8.0 - Info Disclosure
CVSS 5.3
CVE-2025-27721 HIGH
INFINITT PACS System Manager - Info Disclosure
CVSS 7.5
CVE-2025-48355 MEDIUM
ProveSource Social Proof <3.0.5 - Info Disclosure
CVSS 5.3
CVE-2025-2988 LOW
IBM Sterling B2B Integrator & File Gateway <6.2.1 - Info Disclosure
CVSS 2.7
CVE-2025-54736 MEDIUM
NordicMade Savoy <3.0.8 - Info Disclosure
CVSS 5.3
CVE-2025-23288 LOW
NVIDIA GPU Display Driver - Info Disclosure
CVSS 3.3
CVE-2025-23287 LOW
NVIDIA GPU Display Driver - Info Disclosure
CVSS 3.3
CVE-2025-54422 MEDIUM
Sandboxie < 1.16.2 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2025-53031 MEDIUM
Oracle Financial Services Analytical Applications Infrastructure <8...
CVSS 5.3
CVE-2025-53862 LOW
Ansible - Info Disclosure
CVSS 3.5
CVE-2025-6390 MEDIUM
Brocade SANnav <2.4.0a - Info Disclosure
CVSS 4.4
Details
Vulnerabilities 311