CWE-598
Use of HTTP Request With Sensitive Query String
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
87 vulnerabilities with CWE-598
CVE-2025-26058
MEDIUM
Webkul QloApps <1.6.1 - Info Disclosure
CVSS 4.2
CVE-2025-26473
HIGH
OutBack Power Mojave Inverter OGHI8048A Firmware - Sensitive Information Exposure via HTTP GET Request
CVSS 7.5
CVE-2025-0730
LOW
TP-Link TL-SG108E <1.0.0 Build 20201208 Rel. 40304 - Use After Free
CVSS 3.7
CVE-2025-22387
HIGH
Optimizely Configured Commerce <5.2.2408 - Info Disclosure
CVSS 7.5
CVE-2024-9877
MEDIUM
ABB ANC, ANC-L, and ANC-mini <= 1.1.4 - Sensitive Information Exposure via GET Request Query Strings
CVSS 4.3
CVE-2024-12012
MEDIUM
130.8005 TCP/IP Gateway <12h - Info Disclosure
CVSS 5.7
CVE-2024-41738
MEDIUM
IBM TXSeries for Multiplatforms 10.1 - Info Disclosure
CVSS 5.9
CVE-2024-38863
HIGH
Checkmk <2.3.0p18, <2.2.0p35 and <2.1.0p48 - CSRF Token Exposure via Query Parameters
CVSS 7.5
CVE-2024-32931
MEDIUM
exacqVision Web Service < 24.03 - Authentication Token Exposure via HTTP Query String
CVSS 5.7
CVE-2024-23766
HIGH
HMS Anybus X-Gateway AB7832-F - DoS
CVSS 7.5
CVE-2024-31206
HIGH
dectalk-tts <1.0.1 - Info Disclosure
CVSS 8.2
CVE-2024-2745
LOW
Rapid7 InsightVM <6.6.244 - Info Disclosure
CVSS 3.3
CVE-2024-28238
LOW
Directus < 10.10.0 - Session Token Exposure via /files URL Parameter
CVSS 2.3
CVE-2023-50954
MEDIUM
IBM InfoSphere Information Server 11.7 - Info Disclosure
CVSS 4.3
CVE-2023-32335
LOW
IBM Maximo Suite 8.10-8.11 & Asset Mgmt 7.6.1.3 - Sensitive Info Exposure via URL
CVSS 3.7
CVE-2023-45716
LOW
HCL Sametime < 12.0.2 - Cleartext Transmission of Sensitive Information via URL
CVSS 1.7
CVE-2023-50328
LOW
IBM PowerSC 1.3, 2.0, 2.1 - Session Identifier Exposure via URL Query String
CVSS 3.7
CVE-2023-6287
LOW
Tribe29 Checkmk Appliance <1.6.8 - Info Disclosure
CVSS 3.3
CVE-2023-6014
CRITICAL
MLflow < 2.8.0 - Authentication Bypass
CVSS 9.8
CVE-2023-37935
MEDIUM
Fortinet FortiOS <7.0.12-7.2.5-7.4.0 - Info Disclosure
CVSS 6.5
CVE-2023-25524
MEDIUM
NVIDIA Omniverse Launcher < 1.8.11 - Access Token Exposure in Browser Address Bar
CVSS 4.0
CVE-2023-22307
MEDIUM
Tribe29 Checkmk Appliance <1.6.4 - Info Disclosure
CVSS 5.5
CVE-2022-34452
LOW
Dell PowerPath Management Appliance 3.0-3.3 - Authenticated Sensitive Information Disclosure via Log Files
CVSS 2.7
CVE-2022-24414
HIGH
Dell EMC CloudLink <7.1.3 - Info Disclosure
CVSS 7.6
CVE-2022-25787
HIGH
Secomea GateManager < 9.7.622134021 - Information Exposure via LMM API Query Strings
CVSS 7.5
Details
Vulnerabilities
87