Skip to content
Noroxi

CWE-359 · 192 records

Exposure of Private Personal Information to an Unauthorized Actor

CVEs in this class

192 records

  • Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments

    CriticalCVSS 9.1Proof of conceptEPSS 44%

    easyappointments · easyappointmentsMar 9, 2022

  • Azure CLI REST Command Information Disclosure Vulnerability

    HighCVSS 8.6No exploitEPSS 21%

    microsoft · azure command-line interfaceNov 14, 2023

  • Visual Studio Code Jupyter Extension Spoofing Vulnerability

    CriticalCVSS 9.8No exploitEPSS 2%

    microsoft · jupyterNov 14, 2023

  • Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user

    CriticalCVSS 9.3No exploitEPSS 0%

    sparxsystems · pro cloud serverApr 17, 2026

  • Bypass of Discourse Connect using other login paths if enabled in Discourse

    CriticalCVSS 9.1No exploitEPSS 0%

    discourse · discourseDec 19, 2024

  • CVE-2022-2921
    35Monitor

    Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserp

    HighCVSS 8.8No exploitEPSS 1%

    notrinos · notrinoserpAug 21, 2022

  • XWiki Platform: Password and email exposure in xml.vm fields

    HighCVSS 8.7Proof of conceptEPSS 1%

    xwiki · xwikiAug 5, 2025

  • Joomla! Component JoomProject 1.1.3.2 Information Disclosure

    HighCVSS 8.7No exploitEPSS 1%

    joomboost · joomprojectJun 19, 2026

  • phpUploader < 2.0.2 Unauthenticated Database Exposure via index model

    HighCVSS 8.7No exploitEPSS 1%

    shimosyan · phpuploaderJun 29, 2026

  • 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints

    HighCVSS 8.7No exploitEPSS 1%

    decolua · 9routerJul 13, 2026

  • AVideo Platform 8.1 - Information Disclosure (User Enumeration)

    HighCVSS 8.7No exploitEPSS 1%

    wwbn · avideoFeb 11, 2026

  • Session Token Disclosure in M-Files Web

    HighCVSS 8.6No exploitEPSS 0%

    m-files corporation · m-files serverDec 19, 2025

  • DynamicPageList3 exposes hidden/suppressed usernames

    HighCVSS 8.7No exploitEPSS 0%

    universal-omega · dynamicpagelist3Jul 10, 2025

  • Parameter Manipulation Vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    apexsoftcell · ld geoSep 19, 2024

  • Information Disclosure Vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    apexsoftcell · ld geoSep 19, 2024

  • Information Disclosure Vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    reedos · aim-starSep 11, 2024

  • Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actor

    HighCVSS 8.7No exploitEPSS 0%

    dario health · usb-c blood glucose monitoring system starter kit android applicationsFeb 28, 2025

  • Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id

    HighCVSS 8.3No exploitEPSS 0%

    hieventsdev · hi.eventsJun 29, 2026

  • Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.

    HighCVSS 8.3No exploitEPSS 0%

    rti · connext professionalDec 16, 2025

  • Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    HighCVSS 8.2No exploitEPSS 2%

    microsoft · edge chromiumFeb 23, 2024

  • CVE-2025-0683
    32Monitor

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitor

    HighCVSS 8.2No exploitEPSS 1%

    contec health · cms8000 patient monitorJan 30, 2025

  • A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versio

    HighCVSS 8.2No exploitEPSS 1%

    siemens · simatic pcs 7 v9.1Jul 9, 2024

  • Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to

    HighCVSS 8.1No exploitEPSS 1%

    apache · cloudstackMay 8, 2026

  • Improper Access Control in Premierturk's Excavation Management Information System

    HighCVSS 8.1No exploitEPSS 0%

    premierturk information technologies inc. · excavation management information systemNov 11, 2025

  • CVE-2021-3980
    30Monitor

    Exposure of Private Personal Information to an Unauthorized Actor in elgg/elgg

    HighCVSS 7.5No exploitEPSS 2%

    elgg · elggDec 3, 2021

All vulnerability classes