CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

311 vulnerabilities with CWE-497
CVE-2025-30011 MEDIUM
SAP Supplier Relationship Management - Info Disclosure
CVSS 5.3
CVE-2025-46747 MEDIUM
User Management < unknown - Info Disclosure
CVSS 5.7
CVE-2025-46718 LOW
sudo-rs <0.2.6 - Info Disclosure
CVSS 3.3
CVE-2025-46717 LOW
sudo-rs <0.2.6 - Info Disclosure
CVSS 3.3
CVE-2025-3506 MEDIUM
Checkmk <2.4.0b6 - Info Disclosure
CVSS 5.3
CVE-2025-47540 MEDIUM
weMail <1.14.13 - Info Disclosure
CVSS 5.3
CVE-2025-3606 HIGH
Vestel AC Charger 3.75.0 - Info Disclosure
CVSS 7.5
CVE-2025-46421 MEDIUM
Libsoup - Open Redirect
CVSS 6.8
CVE-2025-32792 HIGH
SES <1.12.0 - Info Disclosure
CVE-2025-39439 MEDIUM
wpLike2Get <1.2.9 - Info Disclosure
CVSS 5.3
CVE-2025-39589 MEDIUM
WPDeveloper Essential Addons for Elementor <6.1.9 - Info Disclosure
CVSS 4.3
CVE-2025-39556 MEDIUM
Mediavine Control Panel <2.10.6 - Info Disclosure
CVSS 5.3
CVE-2025-26730 HIGH
NotFound Macro Calculator - Info Disclosure
CVSS 7.5
CVE-2025-30686 HIGH
Oracle Hospitality Simphony < 19.7 - Denial of Service
CVSS 7.6
CVE-2025-32228 MEDIUM
WP Messiah Ai Image Alt Text Generator <1.0.8 - Info Disclosure
CVSS 4.3
CVE-2025-31003 LOW
Bogdan Bendziukov Squeeze - Info Disclosure
CVSS 2.7
CVE-2025-27934 HIGH
Wi-Fi AP UNIT AC-WPS-11ac - Info Disclosure
CVSS 7.5
CVE-2025-32164 MEDIUM
maennchen1.de m1.DownloadList - Info Disclosure
CVSS 6.5
CVE-2025-32026 LOW
Element Web <1.11.96 - Info Disclosure
CVSS 3.8
CVE-2025-32255 MEDIUM
ERA404 StaffList <3.2.6 - Info Disclosure
CVSS 5.3
CVE-2025-32251 MEDIUM
J. Tyler Wiest Jetpack Feedback Exporter <1.23 - Info Disclosure
CVSS 5.3
CVE-2025-0278 MEDIUM
HCL Traveler - Info Disclosure
CVSS 4.3
CVE-2025-31832 MEDIUM
Beee ACF City Selector <1.16.0 - Info Disclosure
CVSS 5.3
CVE-2025-30802 MEDIUM
WPBean <2.2 - Info Disclosure
CVSS 4.3
CVE-2025-27149 LOW
Zulip <10.0 - Info Disclosure
CVSS 2.7
Details
Vulnerabilities 311