CWE-598
Use of HTTP Request With Sensitive Query String
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
87 vulnerabilities with CWE-598
CVE-2025-13219
MEDIUM
IBM Aspera Orchestrator 3.0.0-4.1.2 - Info Disclosure
CVSS 5.9
CVE-2025-41772
HIGH
mbs-solutions universal_bacnet_router_firmware < 6.0.1.0 - Session Token Exposure via wwwupdate.cgi
CVSS 7.5
CVE-2025-59873
MEDIUM
HCL ZIE for Web v16 - Info Disclosure
CVSS 5.9
CVE-2025-69634
CRITICAL
Dolibarr ERP & CRM 22.0.9 - Cross-Site Request Forgery via Notes Field in perms.php
CVSS 9.0
CVE-2025-69270
CRITICAL
Broadcom DX NetOps Spectrum <24.3.8 - Info Disclosure
CVSS 9.8
CVE-2025-36371
MEDIUM
IBM i 7.2-7.6 - Unauthorized Information Disclosure in Database Plan Cache
CVSS 6.5
CVE-2025-31954
MEDIUM
HCL iAutomate 6.5.1-6.5.2 - Sensitive Information Disclosure via HTTP Query String
CVSS 5.4
CVE-2025-32916
MEDIUM
Checkmk GmbH Checkmk <2.4.0p13-2.1.0 - Info Disclosure
CVSS 4.3
CVE-2025-58584
MEDIUM
SICK Baggage Analytics < 4.6.3 - Credential Exposure via URL Query Parameters
CVSS 5.3
CVE-2025-56551
HIGH
DirectAdmin 1.680 - Unauthenticated Login Interface Spoofing via Crafted GET Request
CVSS 8.2
CVE-2025-50709
MEDIUM
Perplexity AI GPT-4 - Info Disclosure
CVSS 4.3
CVE-2025-50110
HIGH
AVTECH EagleEyes Lite <2.0.0 - Info Disclosure
CVSS 8.8
CVE-2025-54542
MEDIUM
QuickCMS 6.8 - Credential Exposure via GET Request
CVSS 5.5
CVE-2025-8997
MEDIUM
OpenText Enterprise Security Manager - Info Disclosure
CVE-2025-57800
HIGH
Audiobookshelf <2.26.3 - Open Redirect
CVSS 8.8
CVE-2025-51651
MEDIUM
Mccms 2.7.0 - Authenticated Arbitrary File Download via Backups.php
CVSS 5.5
CVE-2025-40742
MEDIUM
SIPROTEC 5 - Session Identifier Exposure via URL Query String
CVSS 5.3
CVE-2025-52901
MEDIUM
File Browser <2.33.9 - Info Disclosure
CVSS 4.5
CVE-2025-49188
MEDIUM
Sick Field Analytics - Information Disclosure via URL Parameters
CVSS 5.3
CVE-2025-3943
MEDIUM
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Parameter Injection
CVSS 4.1
CVE-2025-3637
LOW
Moodle < 4.3.12 - Sensitive Query String Exposure in mod_data Edit and Delete Pages
CVSS 3.1
CVE-2025-32021
LOW
Weblate < 5.11 - Sensitive Information Exposure via Repository URL Query Parameter
CVSS 2.2
CVE-2025-24948
MEDIUM
JotUrl 2.0 - Credential Exposure via HTTP GET Request
CVSS 6.5
CVE-2025-2356
LOW
BlackVue App 3.65 - Sensitive Query String Exposure via API Handler
CVSS 3.7
CVE-2025-1738
MEDIUM
Trivision Camera NC227WF <5.8.0 - Info Disclosure
CVSS 6.2
Details
Vulnerabilities
87