CWE-202 · 36 records
Exposure of Sensitive Information Through Data Queries
CVEs in this class
36 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2021-32743No exploit | Passwords used to access external services inadvertently exposed through APIicinga · icinga · CWE-202 | High8.8 | — | 1.8% | Jul 15, 2021 |
33Monitor | CVE-2025-25205Weaponized | Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matchingaudiobookshelf · audiobookshelf · CWE-202 | High8.2 | — | 4.8% | Feb 12, 2025 |
32Monitor | CVE-2024-6400No exploit | Cleartext Storage of Username and Password in Finrota's Netahsilatfinrota · finrota · CWE-202 | High8.2 | — | 0.6% | Oct 4, 2024 |
31Monitor | CVE-2025-69200Proof of concept | phpMyFAQ has unauthenticated config backup download via /api/setup/backupphpmyfaq · phpmyfaq · CWE-202 | High7.5 | — | 2.1% | Dec 29, 2025 |
30Monitor | CVE-2022-41623No exploit | WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerabilityvillatheme · dropshipping and fulfillment for aliexpress and woocommerce · CWE-202 | High7.5 | — | 0.8% | Oct 14, 2022 |
30Monitor | CVE-2023-7072No exploit | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpointpickplugins · post grid combo · CWE-202 | High7.5 | — | 0.6% | Mar 12, 2024 |
30Monitor | CVE-2026-30778No exploit | Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.apache · skywalking · CWE-202 | High7.5 | — | 0.6% | Apr 15, 2026 |
30Monitor | CVE-2024-13255No exploit | RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019restful web services project · restful web services · CWE-202 | High7.5 | — | 0.5% | Jan 9, 2025 |
30Monitor | CVE-2025-29981No exploit | Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.dell · wyse management suite · CWE-202 | High7.5 | — | 0.4% | Apr 1, 2025 |
30Monitor | CVE-2025-36575No exploit | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.dell · wyse management suite · CWE-202 | High7.5 | — | 0.3% | Jun 10, 2025 |
29Monitor | CVE-2026-25703Proof of concept | Potential information leakage from manager /network/graph API in NeuVectorsuse · neuvector · CWE-202 | High7.3 | — | 0.8% | Aug 5, 2026 |
28Monitor | CVE-2025-68456No exploit | Unauthenticated Craft CMS users can trigger a database backupcraftcms · craft cms · CWE-202 | High7.0 | — | 0.6% | Jan 5, 2026 |
26Monitor | CVE-2022-20747No exploit | Cisco SD-WAN vManage Software Information Disclosure Vulnerabilitycisco · catalyst sd-wan manager · CWE-202 | Medium6.5 | — | 0.9% | Apr 15, 2022 |
26Monitor | CVE-2022-20810No exploit | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerabilitycisco · ios xe · CWE-202 | Medium6.5 | — | 0.8% | Sep 30, 2022 |
26Monitor | CVE-2024-1287No exploit | Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQListrangerstudios · paid memberships pro · CWE-202 | Medium6.5 | — | 0.5% | Jul 30, 2024 |
26Monitor | CVE-2024-38892No exploit | An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.wavlink · wn551k1 firmware · CWE-202 | Medium6.5 | — | 0.4% | Jun 24, 2024 |
26Monitor | CVE-2024-2088No exploit | NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposurenextscripts · social networks auto poster · CWE-202 | Medium6.5 | — | 0.3% | May 22, 2024 |
26Monitor | CVE-2026-33530No exploit | InvenTree Vulnerable to ORM Filter Injectioninventree project · inventree · CWE-202 | Medium6.5 | — | 0.2% | Mar 26, 2026 |
25Monitor | CVE-2025-64528No exploit | Users are able to find users by name even when `enable_names` is offdiscourse · discourse · CWE-202 | Medium6.3 | — | 0.3% | Dec 30, 2025 |
22Monitor | CVE-2021-1372No exploit | Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerabilitycisco · webex meetings · CWE-202 | Medium5.5 | — | 0.4% | Feb 17, 2021 |
21Monitor | CVE-2023-20215No exploit | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacisco · asyncos · CWE-202 | Medium5.3 | — | 0.6% | Aug 3, 2023 |
21Monitor | CVE-2024-20388No exploit | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote atcisco · firepower management center · CWE-202 | Medium5.3 | — | 0.4% | Oct 23, 2024 |
21Monitor | CVE-2024-38897No exploit | WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.wavlink · wn551k1 firmware · CWE-202 | Medium5.3 | — | 0.4% | Jun 24, 2024 |
21Monitor | CVE-2026-3546No exploit | e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJforfront · e-shot · CWE-202 | Medium5.3 | — | 0.4% | Mar 21, 2026 |
21Monitor | CVE-2024-38895No exploit | WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.wavlink · wn551k1 firmware · CWE-202 | Medium5.3 | — | 0.4% | Jun 24, 2024 |
- CVE-2021-3274336Monitor
Passwords used to access external services inadvertently exposed through API
HighCVSS 8.8No exploitEPSS 2%icinga · icingaJul 15, 2021
- CVE-2025-2520533Monitor
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
HighCVSS 8.2WeaponizedEPSS 5%audiobookshelf · audiobookshelfFeb 12, 2025
- CVE-2024-640032Monitor
Cleartext Storage of Username and Password in Finrota's Netahsilat
HighCVSS 8.2No exploitEPSS 1%finrota · finrotaOct 4, 2024
- CVE-2025-6920031Monitor
phpMyFAQ has unauthenticated config backup download via /api/setup/backup
HighCVSS 7.5Proof of conceptEPSS 2%phpmyfaq · phpmyfaqDec 29, 2025
- CVE-2022-4162330Monitor
WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerability
HighCVSS 7.5No exploitEPSS 1%villatheme · dropshipping and fulfillment for aliexpress and woocommerceOct 14, 2022
- CVE-2023-707230Monitor
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint
HighCVSS 7.5No exploitEPSS 1%pickplugins · post grid comboMar 12, 2024
- CVE-2026-3077830Monitor
Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
HighCVSS 7.5No exploitEPSS 1%apache · skywalkingApr 15, 2026
- CVE-2024-1325530Monitor
RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019
HighCVSS 7.5No exploitEPSS 1%restful web services project · restful web servicesJan 9, 2025
- CVE-2025-2998130Monitor
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.
HighCVSS 7.5No exploitEPSS 0%dell · wyse management suiteApr 1, 2025
- CVE-2025-3657530Monitor
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.
HighCVSS 7.5No exploitEPSS 0%dell · wyse management suiteJun 10, 2025
- CVE-2026-2570329Monitor
Potential information leakage from manager /network/graph API in NeuVector
HighCVSS 7.3Proof of conceptEPSS 1%suse · neuvectorAug 5, 2026
- CVE-2025-6845628Monitor
Unauthenticated Craft CMS users can trigger a database backup
HighCVSS 7.0No exploitEPSS 1%craftcms · craft cmsJan 5, 2026
- CVE-2022-2074726Monitor
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
MediumCVSS 6.5No exploitEPSS 1%cisco · catalyst sd-wan managerApr 15, 2022
- CVE-2022-2081026Monitor
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerability
MediumCVSS 6.5No exploitEPSS 1%cisco · ios xeSep 30, 2022
- CVE-2024-128726Monitor
Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi
MediumCVSS 6.5No exploitEPSS 1%strangerstudios · paid memberships proJul 30, 2024
- CVE-2024-3889226Monitor
An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.
MediumCVSS 6.5No exploitEPSS 0%wavlink · wn551k1 firmwareJun 24, 2024
- CVE-2024-208826Monitor
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure
MediumCVSS 6.5No exploitEPSS 0%nextscripts · social networks auto posterMay 22, 2024
- CVE-2026-3353026Monitor
InvenTree Vulnerable to ORM Filter Injection
MediumCVSS 6.5No exploitEPSS 0%inventree project · inventreeMar 26, 2026
- CVE-2025-6452825Monitor
Users are able to find users by name even when `enable_names` is off
MediumCVSS 6.3No exploitEPSS 0%discourse · discourseDec 30, 2025
- CVE-2021-137222Monitor
Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability
MediumCVSS 5.5No exploitEPSS 0%cisco · webex meetingsFeb 17, 2021
- CVE-2023-2021521Monitor
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote atta
MediumCVSS 5.3No exploitEPSS 1%cisco · asyncosAug 3, 2023
- CVE-2024-2038821Monitor
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote at
MediumCVSS 5.3No exploitEPSS 0%cisco · firepower management centerOct 23, 2024
- CVE-2024-3889721Monitor
WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
MediumCVSS 5.3No exploitEPSS 0%wavlink · wn551k1 firmwareJun 24, 2024
- CVE-2026-354621Monitor
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJ
MediumCVSS 5.3No exploitEPSS 0%forfront · e-shotMar 21, 2026
- CVE-2024-3889521Monitor
WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.
MediumCVSS 5.3No exploitEPSS 0%wavlink · wn551k1 firmwareJun 24, 2024