CWE-213 · 32 kayıt
Exposure of Sensitive Information Due to Incompatible Policies
Bu sınıftaki CVE’ler
32 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-1652İstismar yok | Junos Space: OpenNMS is accessible via port 9443opennms · opennms · CWE-213 | Kritik9,8 | — | %0,7 | 17 Tem 2020 |
36İzleyin | CVE-2023-3441İstismar yok | Exposure of Sensitive Information Due to Incompatible Policies in GitLabgitlab · gitlab · CWE-213 | Kritik9,1 | — | %0,6 | 1 Eki 2024 |
30İzleyin | CVE-2019-1010283İstismar yok | Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure.univention · univention corporate server · CWE-213 | Yüksek7,5 | — | %1,4 | 17 Tem 2019 |
30İzleyin | CVE-2022-30350İstismar yok | Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure.avanquest · pdfescape · CWE-213 | Yüksek7,5 | — | %0,7 | 30 Mar 2023 |
30İzleyin | CVE-2023-6517İstismar yok | Seeing the SMS Verification Code in Mia Technology's Mia-Medmiateknoloji · mia-med · CWE-213 | Yüksek7,5 | — | %0,5 | 8 Şub 2024 |
30İzleyin | CVE-2024-49354İstismar yok | IBM Concert information disclosureibm · concert · CWE-213 | Yüksek7,5 | — | %0,3 | 18 Oca 2025 |
30İzleyin | CVE-2024-49827İstismar yok | IBM Concert Software information disclosureibm · concert · CWE-213 | Yüksek7,5 | — | %0,2 | 18 Ağu 2025 |
28İzleyin | CVE-2024-7267İstismar yok | Internal infrastructure data leak in EZD RPnask · ezd rp · CWE-213 | Yüksek7,1 | — | %0,6 | 7 Ağu 2024 |
27İzleyin | CVE-2025-24316İstismar yok | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policiesdario health · dario application database and internet-based server infrastructure · CWE-213 | Orta6,9 | — | %0,3 | 28 Şub 2025 |
26İzleyin | CVE-2025-54831İstismar yok | Apache Airflow: Connection sensitive details exposed to users with READ permissionsapache · airflow · CWE-213 | Orta6,5 | — | %0,9 | 26 Eyl 2025 |
26İzleyin | CVE-2022-22541İstismar yok | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see sap · businessobjects business intelligence platform · CWE-213 | Orta6,5 | — | %0,8 | 12 Nis 2022 |
26İzleyin | CVE-2026-6280İstismar yok | Improper Access Control in Nomysoft Informatics' Nomysemnomysoft informatics education and consulting inc. · nomysem · CWE-213 | Orta6,5 | — | %0,4 | 8 Tem 2026 |
23İzleyin | CVE-2019-10247İstismar yok | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version eclipse · jetty · CWE-213 | Orta5,3 | — | %5,9 | 22 Nis 2019 |
22İzleyin | CVE-2019-10246İstismar yok | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Reseclipse · jetty · CWE-213 | Orta5,3 | — | %4,1 | 22 Nis 2019 |
21İzleyin | CVE-2017-3211İstismar yok | Centire Yopify leaks customer informationyopify · yopify · CWE-213 | Orta5,3 | — | %0,8 | 15 Oca 2020 |
21İzleyin | CVE-2023-40570İstismar yok | Datasette 1.0 alpha series leaks names of databases and tables to unauthenticated usersdatasette · datasette · CWE-213 | Orta5,3 | — | %0,6 | 24 Ağu 2023 |
21İzleyin | CVE-2023-36919İstismar yok | Information Disclosure in SAP Enable Nowsap · enable now · CWE-213 | Orta5,3 | — | %0,5 | 10 Tem 2023 |
21İzleyin | CVE-2025-4976İstismar yok | Exposure of Sensitive Information Due to Incompatible Policies in GitLabgitlab · gitlab · CWE-213 | Orta5,3 | — | %0,4 | 24 Tem 2025 |
20İzleyin | CVE-2026-55425İstismar yok | Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fieldsgraylog2 · graylog2-server · CWE-213 | Orta5,0 | — | %0,4 | 28 Ağu 2026 |
18İzleyin | CVE-2023-27465İstismar yok | A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1), siemens · simotion d425-2 dp firmware · CWE-213 | Orta4,6 | — | %0,3 | 13 Haz 2023 |
17İzleyin | CVE-2024-44121İstismar yok | Information Disclosure in SAP S/4 HANA (Statutory Reports)sap_se · sap s/4 hana (statutory reports) · CWE-213 | Orta4,3 | — | %0,3 | 10 Eyl 2024 |
17İzleyin | CVE-2025-32791İstismar yok | Permission policy information leakage in Backstage permission systembackstage · backstage · CWE-213 | Orta4,3 | — | %0,3 | 16 Nis 2025 |
14İzleyin | CVE-2023-5117İstismar yok | Exposure of Sensitive Information Due to Incompatible Policies in GitLabgitlab · gitlab · CWE-213 | Düşük3,7 | — | %0,3 | 25 Ara 2024 |
14İzleyin | CVE-2026-56538İstismar yok | HCL Connections is vulnerable to information disclosurehcltech · connections · CWE-213 | Düşük3,5 | — | %0,3 | 27 Tem 2026 |
14İzleyin | CVE-2025-52603İstismar yok | HCL Connections is vulnerable to information disclosurehcltech · connections · CWE-213 | Düşük3,5 | — | %0,3 | 20 Şub 2026 |
- CVE-2020-165239İzleyin
Junos Space: OpenNMS is accessible via port 9443
KritikCVSS 9,8İstismar yokEPSS %1opennms · opennms17 Tem 2020
- CVE-2023-344136İzleyin
Exposure of Sensitive Information Due to Incompatible Policies in GitLab
KritikCVSS 9,1İstismar yokEPSS %1gitlab · gitlab1 Eki 2024
- CVE-2019-101028330İzleyin
Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure.
YüksekCVSS 7,5İstismar yokEPSS %1univention · univention corporate server17 Tem 2019
- CVE-2022-3035030İzleyin
Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure.
YüksekCVSS 7,5İstismar yokEPSS %1avanquest · pdfescape30 Mar 2023
- CVE-2023-651730İzleyin
Seeing the SMS Verification Code in Mia Technology's Mia-Med
YüksekCVSS 7,5İstismar yokEPSS %0miateknoloji · mia-med8 Şub 2024
- CVE-2024-4935430İzleyin
IBM Concert information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · concert18 Oca 2025
- CVE-2024-4982730İzleyin
IBM Concert Software information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · concert18 Ağu 2025
- CVE-2024-726728İzleyin
Internal infrastructure data leak in EZD RP
YüksekCVSS 7,1İstismar yokEPSS %1nask · ezd rp7 Ağu 2024
- CVE-2025-2431627İzleyin
Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policies
OrtaCVSS 6,9İstismar yokEPSS %0dario health · dario application database and internet-based server infrastructure28 Şub 2025
- CVE-2025-5483126İzleyin
Apache Airflow: Connection sensitive details exposed to users with READ permissions
OrtaCVSS 6,5İstismar yokEPSS %1apache · airflow26 Eyl 2025
- CVE-2022-2254126İzleyin
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see
OrtaCVSS 6,5İstismar yokEPSS %1sap · businessobjects business intelligence platform12 Nis 2022
- CVE-2026-628026İzleyin
Improper Access Control in Nomysoft Informatics' Nomysem
OrtaCVSS 6,5İstismar yokEPSS %0nomysoft informatics education and consulting inc. · nomysem8 Tem 2026
- CVE-2019-1024723İzleyin
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version
OrtaCVSS 5,3İstismar yokEPSS %6eclipse · jetty22 Nis 2019
- CVE-2019-1024622İzleyin
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Res
OrtaCVSS 5,3İstismar yokEPSS %4eclipse · jetty22 Nis 2019
- CVE-2017-321121İzleyin
Centire Yopify leaks customer information
OrtaCVSS 5,3İstismar yokEPSS %1yopify · yopify15 Oca 2020
- CVE-2023-4057021İzleyin
Datasette 1.0 alpha series leaks names of databases and tables to unauthenticated users
OrtaCVSS 5,3İstismar yokEPSS %1datasette · datasette24 Ağu 2023
- CVE-2023-3691921İzleyin
Information Disclosure in SAP Enable Now
OrtaCVSS 5,3İstismar yokEPSS %0sap · enable now10 Tem 2023
- CVE-2025-497621İzleyin
Exposure of Sensitive Information Due to Incompatible Policies in GitLab
OrtaCVSS 5,3İstismar yokEPSS %0gitlab · gitlab24 Tem 2025
- CVE-2026-5542520İzleyin
Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields
OrtaCVSS 5,0İstismar yokEPSS %0graylog2 · graylog2-server28 Ağu 2026
- CVE-2023-2746518İzleyin
A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1),
OrtaCVSS 4,6İstismar yokEPSS %0siemens · simotion d425-2 dp firmware13 Haz 2023
- CVE-2024-4412117İzleyin
Information Disclosure in SAP S/4 HANA (Statutory Reports)
OrtaCVSS 4,3İstismar yokEPSS %0sap_se · sap s/4 hana (statutory reports)10 Eyl 2024
- CVE-2025-3279117İzleyin
Permission policy information leakage in Backstage permission system
OrtaCVSS 4,3İstismar yokEPSS %0backstage · backstage16 Nis 2025
- CVE-2023-511714İzleyin
Exposure of Sensitive Information Due to Incompatible Policies in GitLab
DüşükCVSS 3,7İstismar yokEPSS %0gitlab · gitlab25 Ara 2024
- CVE-2026-5653814İzleyin
HCL Connections is vulnerable to information disclosure
DüşükCVSS 3,5İstismar yokEPSS %0hcltech · connections27 Tem 2026
- CVE-2025-5260314İzleyin
HCL Connections is vulnerable to information disclosure
DüşükCVSS 3,5İstismar yokEPSS %0hcltech · connections20 Şub 2026