CWE-497 · 398 kayıt
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Bu sınıftaki CVE’ler
398 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
76Bu hafta | CVE-2021-31955Silahlaştırılmış | Windows Kernel Information Disclosure Vulnerabilitymicrosoft · windows 10 1809 · CWE-497 | Orta5,5 | KEV | %81,1 | 8 Haz 2021 |
40Planlayın | CVE-2025-44823Kavram kanıtı | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.phnagios · log server · CWE-497 | Yüksek8,8 | — | %16,1 | 7 Eki 2025 |
40Planlayın | CVE-2025-10264İstismar yok | Digiever|NVR - Exposure of Sensitive Informationdigiever · ds-1200 · CWE-497 | Kritik10,0 | — | %0,5 | 12 Eyl 2025 |
39İzleyin | CVE-2020-25179İstismar yok | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.gehealthcare · 3.0t signa hdxt firmware · CWE-497 | Kritik9,8 | — | %1,5 | 14 Ara 2020 |
39İzleyin | CVE-2025-1144İstismar yok | Quanxun School Affairs System - Exposure of Sensitive Informationquanxun · school affairs system · CWE-497 | Kritik9,8 | — | %0,5 | 11 Şub 2025 |
39İzleyin | CVE-2024-36554İstismar yok | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0CWE-497 | Kritik9,8 | — | %0,4 | 6 Şub 2025 |
39İzleyin | CVE-2025-47699İstismar yok | Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authgallagher · command centre server · CWE-497 | Kritik9,9 | — | %0,3 | 23 Eki 2025 |
38İzleyin | CVE-2025-11545İstismar yok | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attasharp display solutions, ltd. · np-pa1705ul-w, np-pa1705ul-w+, np-pa1705ul-b, np-pa1705ul-b+, np-pa1505ul-w, np-pa1505ul-w+, np-pa1505ul-b, np-pa1505ul-b+, np-pa1505ul-bjl np-pv800ul-w, np-pv800ul-w+, np-pv800ul-b, np-pv800ul-b+, np · CWE-497 | Kritik9,5 | — | %0,3 | 22 Ara 2025 |
37İzleyin | CVE-2026-14808İstismar yok | PROG MIS|Prog Management System - Exposure of Sensitive Informationprog mis · prog management system · CWE-497 | Kritik9,3 | — | %0,7 | 6 Tem 2026 |
36İzleyin | CVE-2026-34413Silahlaştırılmış | Xerte Online Toolkits Missing Authentication via connector.phpthexerteproject · xerteonlinetoolkits · CWE-497 | Yüksek8,8 | — | %3,1 | 22 Nis 2026 |
36İzleyin | CVE-2025-0061İstismar yok | Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platformsap · businessobjects business intelligence platform · CWE-497 | Kritik9,1 | — | %0,5 | 13 Oca 2025 |
36İzleyin | CVE-2026-28698İstismar yok | Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqspronetiqs · panduit intravue · CWE-497 | Kritik9,2 | — | %0,4 | 23 Tem 2026 |
35İzleyin | CVE-2022-1902İstismar yok | A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes.redhat · advanced cluster security · CWE-497 | Yüksek8,8 | — | %1,4 | 1 Eyl 2022 |
35İzleyin | CVE-2025-12779İstismar yok | Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authamazon · amazon workspaces · CWE-497 | Yüksek8,8 | — | %0,2 | 5 Kas 2025 |
34İzleyin | CVE-2018-25358İstismar yok | D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgid-link · dir-601 · CWE-497 | Yüksek8,7 | — | %0,6 | 23 May 2026 |
34İzleyin | CVE-2025-32792İstismar yok | ses's global contour bindings leak into Compartment lexical scopeendojs · endo · CWE-497 | Yüksek8,7 | — | %0,6 | 18 Nis 2025 |
34İzleyin | CVE-2026-38058İstismar yok | ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Information to an Unauthorized Control Spherest engineering idirect · evolution iq‑series terminals · CWE-497 | Yüksek8,6 | — | %0,5 | 11 Eyl 2026 |
34İzleyin | CVE-2022-4985İstismar yok | Vodafone H500s WiFi Password Disclosure via activation.jsonvodacom · vodafone h500s · CWE-497 | Yüksek8,7 | — | %0,5 | 14 Kas 2025 |
34İzleyin | CVE-2026-66840İstismar yok | XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497).xing inc. · xing cptrans-me-x · CWE-497 | Yüksek8,7 | — | %0,4 | 4 Eyl 2026 |
34İzleyin | CVE-2025-4364İstismar yok | Exposure of Sensitive System Information to an Unauthorized Control Sphereassured telematics inc. · fleet management system · CWE-497 | Yüksek8,7 | — | %0,4 | 20 May 2025 |
34İzleyin | CVE-2024-58375İstismar yok | OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluationopentofu · opentofu · CWE-497 | Yüksek8,7 | — | %0,4 | 16 Ağu 2026 |
34İzleyin | CVE-2025-54459İstismar yok | Vertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control Spherevertikalsystems · hospital manager backend services · CWE-497 | Yüksek8,7 | — | %0,4 | 29 Eki 2025 |
34İzleyin | CVE-2025-59098İstismar yok | Trace Functionality Leaking Sensitive Data in dormakaba access managerdormakaba · access manager 92xx-k5 · CWE-497 | Yüksek8,7 | — | %0,4 | 26 Oca 2026 |
34İzleyin | CVE-2025-3606İstismar yok | Vestel AC Charger Exposure of Sensitive System Information to an Unauthorized Control Spherevestel · ac charger evc04 · CWE-497 | Yüksek8,7 | — | %0,4 | 24 Nis 2025 |
34İzleyin | CVE-2026-24222İstismar yok | NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper anvidia · nemoclaw · CWE-497 | Yüksek8,6 | — | %0,4 | 28 Nis 2026 |
- CVE-2021-3195576Bu hafta
Windows Kernel Information Disclosure Vulnerability
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %81microsoft · windows 10 18098 Haz 2021
- CVE-2025-4482340Planlayın
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.ph
YüksekCVSS 8,8Kavram kanıtıEPSS %16nagios · log server7 Eki 2025
- CVE-2025-1026440Planlayın
Digiever|NVR - Exposure of Sensitive Information
KritikCVSS 10,0İstismar yokEPSS %0digiever · ds-120012 Eyl 2025
- CVE-2020-2517939İzleyin
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
KritikCVSS 9,8İstismar yokEPSS %2gehealthcare · 3.0t signa hdxt firmware14 Ara 2020
- CVE-2025-114439İzleyin
Quanxun School Affairs System - Exposure of Sensitive Information
KritikCVSS 9,8İstismar yokEPSS %1quanxun · school affairs system11 Şub 2025
- CVE-2024-3655439İzleyin
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0
KritikCVSS 9,8İstismar yokEPSS %06 Şub 2025
- CVE-2025-4769939İzleyin
Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an auth
KritikCVSS 9,9İstismar yokEPSS %0gallagher · command centre server23 Eki 2025
- CVE-2025-1154538İzleyin
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a atta
KritikCVSS 9,5İstismar yokEPSS %0sharp display solutions, ltd. · np-pa1705ul-w, np-pa1705ul-w+, np-pa1705ul-b, np-pa1705ul-b+, np-pa1505ul-w, np-pa1505ul-w+, np-pa1505ul-b, np-pa1505ul-b+, np-pa1505ul-bjl np-pv800ul-w, np-pv800ul-w+, np-pv800ul-b, np-pv800ul-b+, np22 Ara 2025
- CVE-2026-1480837İzleyin
PROG MIS|Prog Management System - Exposure of Sensitive Information
KritikCVSS 9,3İstismar yokEPSS %1prog mis · prog management system6 Tem 2026
- CVE-2026-3441336İzleyin
Xerte Online Toolkits Missing Authentication via connector.php
YüksekCVSS 8,8SilahlaştırılmışEPSS %3thexerteproject · xerteonlinetoolkits22 Nis 2026
- CVE-2025-006136İzleyin
Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
KritikCVSS 9,1İstismar yokEPSS %1sap · businessobjects business intelligence platform13 Oca 2025
- CVE-2026-2869836İzleyin
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs
KritikCVSS 9,2İstismar yokEPSS %0pronetiqs · panduit intravue23 Tem 2026
- CVE-2022-190235İzleyin
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes.
YüksekCVSS 8,8İstismar yokEPSS %1redhat · advanced cluster security1 Eyl 2022
- CVE-2025-1277935İzleyin
Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the auth
YüksekCVSS 8,8İstismar yokEPSS %0amazon · amazon workspaces5 Kas 2025
- CVE-2018-2535834İzleyin
D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi
YüksekCVSS 8,7İstismar yokEPSS %1d-link · dir-60123 May 2026
- CVE-2025-3279234İzleyin
ses's global contour bindings leak into Compartment lexical scope
YüksekCVSS 8,7İstismar yokEPSS %1endojs · endo18 Nis 2025
- CVE-2026-3805834İzleyin
ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Information to an Unauthorized Control Sphere
YüksekCVSS 8,6İstismar yokEPSS %0st engineering idirect · evolution iq‑series terminals11 Eyl 2026
- CVE-2022-498534İzleyin
Vodafone H500s WiFi Password Disclosure via activation.json
YüksekCVSS 8,7İstismar yokEPSS %0vodacom · vodafone h500s14 Kas 2025
- CVE-2026-6684034İzleyin
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497).
YüksekCVSS 8,7İstismar yokEPSS %0xing inc. · xing cptrans-me-x4 Eyl 2026
- CVE-2025-436434İzleyin
Exposure of Sensitive System Information to an Unauthorized Control Sphere
YüksekCVSS 8,7İstismar yokEPSS %0assured telematics inc. · fleet management system20 May 2025
- CVE-2024-5837534İzleyin
OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation
YüksekCVSS 8,7İstismar yokEPSS %0opentofu · opentofu16 Ağu 2026
- CVE-2025-5445934İzleyin
Vertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control Sphere
YüksekCVSS 8,7İstismar yokEPSS %0vertikalsystems · hospital manager backend services29 Eki 2025
- CVE-2025-5909834İzleyin
Trace Functionality Leaking Sensitive Data in dormakaba access manager
YüksekCVSS 8,7İstismar yokEPSS %0dormakaba · access manager 92xx-k526 Oca 2026
- CVE-2025-360634İzleyin
Vestel AC Charger Exposure of Sensitive System Information to an Unauthorized Control Sphere
YüksekCVSS 8,7İstismar yokEPSS %0vestel · ac charger evc0424 Nis 2025
- CVE-2026-2422234İzleyin
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper a
YüksekCVSS 8,6İstismar yokEPSS %0nvidia · nemoclaw28 Nis 2026