CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

368 vulnerabilities with CWE-497
CVE-2025-23287 LOW
NVIDIA GPU Display Driver - Info Disclosure
CVSS 3.3
CVE-2025-54422 MEDIUM
Sandboxie < 1.16.2 - Insufficiently Protected Credentials via Shared Memory and Command-Line Arguments
CVSS 5.5
CVE-2025-53031 MEDIUM
Oracle Financial Services Analytical Applications Infrastructure <8...
CVSS 5.3
CVE-2025-53862 LOW
Ansible Automation Platform - Unauthenticated Exposure of Sensitive System Information via API Endpoints
CVSS 3.5
CVE-2025-6390 MEDIUM
Brocade SANnav <2.4.0a - Info Disclosure
CVSS 4.4
CVE-2025-4662 MEDIUM
Brocade SANnav <2.4.0a - Info Disclosure
CVSS 4.4
CVE-2025-53364 MEDIUM
Parse Server <7.5.3-8.2.2 - Info Disclosure
CVSS 5.3
CVE-2025-7381 MEDIUM
Docker Mautic <=6.0.3/5.2.7 PHP Version Exposure via X-Powered-By Header
CVSS 5.3
CVE-2025-2670 MEDIUM
IBM OpenPages 9.0 - Info Disclosure
CVSS 4.3
CVE-2025-27369 MEDIUM
IBM OpenPages with Watson 8.3-9.0 - Info Disclosure
CVSS 4.3
CVE-2025-24334 LOW
Nokia Single RAN <23R2-SR 1.0 MP - Info Disclosure
CVSS 3.3
CVE-2025-53211 MEDIUM
Roland Beaussant Audio Editor &amp; Recorder <2.2.3 - Info Disclosure
CVSS 5.3
CVE-2025-6561 CRITICAL
Hunt Electronic Hybrid DVR - Info Disclosure
CVSS 9.8
CVE-2025-49147 MEDIUM
Umbraco <10.8.10, <13.9.1 - Info Disclosure
CVSS 5.3
CVE-2025-5416 LOW
Keycloak - Authenticated Sensitive Information Exposure via Admin Serverinfo Endpoint
CVSS 2.7
CVE-2025-52719 MEDIUM
Metagauss ProfileGrid <5.9.5.2 - Info Disclosure
CVSS 4.3
CVE-2025-4229 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVE-2025-0036 LOW
AMD Versal Adaptive SoC - Memory Corruption
CVSS 3.2
CVE-2025-31045 HIGH
elfsight Contact Form widget <2.3.1 - Info Disclosure
CVSS 7.5
CVE-2025-5893 CRITICAL
Smart Parking Management System - Info Disclosure
CVSS 9.8
CVE-2025-49419 MEDIUM
Foxit eSign for WordPress <2.0.3 - Info Disclosure
CVSS 5.5
CVE-2025-23969 MEDIUM
whassan KI Live Video Conferences <5.5.15 - Info Disclosure
CVSS 5.3
CVE-2025-24473 LOW
Fortinet FortiClient <7.2.1 - Info Disclosure
CVSS 3.7
CVE-2025-2236 LOW
OpenText Advanced Authentication <6.5 - Info Disclosure
CVE-2025-30170 MEDIUM
ABB ASPECT-Enterprise, NEXUS Series, MATRIX Series <= 3.08.03 - Authenticated Exposure of Sensitive System Information
CVSS 5.5
Details
Vulnerabilities 368