Skip to content
Noroxi

CWE-202 · 36 records

Exposure of Sensitive Information Through Data Queries

CVEs in this class

36 records

  • Passwords used to access external services inadvertently exposed through API

    HighCVSS 8.8No exploitEPSS 2%

    icinga · icingaJul 15, 2021

  • Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching

    HighCVSS 8.2WeaponizedEPSS 5%

    audiobookshelf · audiobookshelfFeb 12, 2025

  • CVE-2024-6400
    32Monitor

    Cleartext Storage of Username and Password in Finrota's Netahsilat

    HighCVSS 8.2No exploitEPSS 1%

    finrota · finrotaOct 4, 2024

  • phpMyFAQ has unauthenticated config backup download via /api/setup/backup

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpmyfaq · phpmyfaqDec 29, 2025

  • WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    villatheme · dropshipping and fulfillment for aliexpress and woocommerceOct 14, 2022

  • CVE-2023-7072
    30Monitor

    Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint

    HighCVSS 7.5No exploitEPSS 1%

    pickplugins · post grid comboMar 12, 2024

  • Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.

    HighCVSS 7.5No exploitEPSS 1%

    apache · skywalkingApr 15, 2026

  • RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019

    HighCVSS 7.5No exploitEPSS 1%

    restful web services project · restful web servicesJan 9, 2025

  • Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.

    HighCVSS 7.5No exploitEPSS 0%

    dell · wyse management suiteApr 1, 2025

  • Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.

    HighCVSS 7.5No exploitEPSS 0%

    dell · wyse management suiteJun 10, 2025

  • Potential information leakage from manager /network/graph API in NeuVector

    HighCVSS 7.3Proof of conceptEPSS 1%

    suse · neuvectorAug 5, 2026

  • Unauthenticated Craft CMS users can trigger a database backup

    HighCVSS 7.0No exploitEPSS 1%

    craftcms · craft cmsJan 5, 2026

  • Cisco SD-WAN vManage Software Information Disclosure Vulnerability

    MediumCVSS 6.5No exploitEPSS 1%

    cisco · catalyst sd-wan managerApr 15, 2022

  • Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerability

    MediumCVSS 6.5No exploitEPSS 1%

    cisco · ios xeSep 30, 2022

  • CVE-2024-1287
    26Monitor

    Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi

    MediumCVSS 6.5No exploitEPSS 1%

    strangerstudios · paid memberships proJul 30, 2024

  • An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

    MediumCVSS 6.5No exploitEPSS 0%

    wavlink · wn551k1 firmwareJun 24, 2024

  • CVE-2024-2088
    26Monitor

    NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure

    MediumCVSS 6.5No exploitEPSS 0%

    nextscripts · social networks auto posterMay 22, 2024

  • InvenTree Vulnerable to ORM Filter Injection

    MediumCVSS 6.5No exploitEPSS 0%

    inventree project · inventreeMar 26, 2026

  • Users are able to find users by name even when `enable_names` is off

    MediumCVSS 6.3No exploitEPSS 0%

    discourse · discourseDec 30, 2025

  • CVE-2021-1372
    22Monitor

    Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability

    MediumCVSS 5.5No exploitEPSS 0%

    cisco · webex meetingsFeb 17, 2021

  • A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote atta

    MediumCVSS 5.3No exploitEPSS 1%

    cisco · asyncosAug 3, 2023

  • A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote at

    MediumCVSS 5.3No exploitEPSS 0%

    cisco · firepower management centerOct 23, 2024

  • WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

    MediumCVSS 5.3No exploitEPSS 0%

    wavlink · wn551k1 firmwareJun 24, 2024

  • CVE-2026-3546
    21Monitor

    e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJ

    MediumCVSS 5.3No exploitEPSS 0%

    forfront · e-shotMar 21, 2026

  • WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

    MediumCVSS 5.3No exploitEPSS 0%

    wavlink · wn551k1 firmwareJun 24, 2024

All vulnerability classes