CWE-359 · 192 records
Exposure of Private Personal Information to an Unauthorized Actor
CVEs in this class
192 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2022-0482Proof of concept | Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-359 | Critical9.1 | — | 43.7% | Mar 9, 2022 |
40Plan | CVE-2023-36052No exploit | Azure CLI REST Command Information Disclosure Vulnerabilitymicrosoft · azure command-line interface · CWE-359 | High8.6 | — | 21.1% | Nov 14, 2023 |
39Monitor | CVE-2023-36018No exploit | Visual Studio Code Jupyter Extension Spoofing Vulnerabilitymicrosoft · jupyter · CWE-359 | Critical9.8 | — | 1.5% | Nov 14, 2023 |
37Monitor | CVE-2025-15623No exploit | Sparx Pro Cloud Server reveals sensitive information to an unauthenticated usersparxsystems · pro cloud server · CWE-359 | Critical9.3 | — | 0.3% | Apr 17, 2026 |
36Monitor | CVE-2024-49765No exploit | Bypass of Discourse Connect using other login paths if enabled in Discoursediscourse · discourse · CWE-359 | Critical9.1 | — | 0.4% | Dec 19, 2024 |
35Monitor | CVE-2022-2921No exploit | Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserpnotrinos · notrinoserp · CWE-359 | High8.8 | — | 1.3% | Aug 21, 2022 |
34Monitor | CVE-2025-54125Proof of concept | XWiki Platform: Password and email exposure in xml.vm fieldsxwiki · xwiki · CWE-359 | High8.7 | — | 1.4% | Aug 5, 2025 |
34Monitor | CVE-2019-25762No exploit | Joomla! Component JoomProject 1.1.3.2 Information Disclosurejoomboost · joomproject · CWE-359 | High8.7 | — | 0.7% | Jun 19, 2026 |
34Monitor | CVE-2026-56124No exploit | phpUploader < 2.0.2 Unauthenticated Database Exposure via index modelshimosyan · phpuploader · CWE-359 | High8.7 | — | 0.6% | Jun 29, 2026 |
34Monitor | CVE-2026-62328No exploit | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpointsdecolua · 9router · CWE-359 | High8.7 | — | 0.6% | Jul 13, 2026 |
34Monitor | CVE-2020-37173No exploit | AVideo Platform 8.1 - Information Disclosure (User Enumeration)wwbn · avideo · CWE-359 | High8.7 | — | 0.6% | Feb 11, 2026 |
34Monitor | CVE-2025-13008No exploit | Session Token Disclosure in M-Files Webm-files corporation · m-files server · CWE-359 | High8.6 | — | 0.5% | Dec 19, 2025 |
34Monitor | CVE-2025-53625No exploit | DynamicPageList3 exposes hidden/suppressed usernamesuniversal-omega · dynamicpagelist3 · CWE-359 | High8.7 | — | 0.5% | Jul 10, 2025 |
34Monitor | CVE-2024-47085No exploit | Parameter Manipulation Vulnerabilityapexsoftcell · ld geo · CWE-359 | High8.7 | — | 0.4% | Sep 19, 2024 |
34Monitor | CVE-2024-47087No exploit | Information Disclosure Vulnerabilityapexsoftcell · ld geo · CWE-359 | High8.7 | — | 0.4% | Sep 19, 2024 |
34Monitor | CVE-2024-45787No exploit | Information Disclosure Vulnerabilityreedos · aim-star · CWE-359 | High8.7 | — | 0.4% | Sep 11, 2024 |
34Monitor | CVE-2025-20060No exploit | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actordario health · usb-c blood glucose monitoring system starter kit android applications · CWE-359 | High8.7 | — | 0.4% | Feb 28, 2025 |
33Monitor | CVE-2026-57960No exploit | Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_idhieventsdev · hi.events · CWE-359 | High8.3 | — | 0.4% | Jun 29, 2026 |
33Monitor | CVE-2025-10450No exploit | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.rti · connext professional · CWE-359 | High8.3 | — | 0.2% | Dec 16, 2025 |
32Monitor | CVE-2024-26192No exploit | Microsoft Edge (Chromium-based) Information Disclosure Vulnerabilitymicrosoft · edge chromium · CWE-359 | High8.2 | — | 1.5% | Feb 23, 2024 |
32Monitor | CVE-2025-0683No exploit | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitorcontec health · cms8000 patient monitor · CWE-359 | High8.2 | — | 0.8% | Jan 30, 2025 |
32Monitor | CVE-2024-30321No exploit | A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versiosiemens · simatic pcs 7 v9.1 · CWE-359 | High8.2 | — | 0.5% | Jul 9, 2024 |
32Monitor | CVE-2025-66172No exploit | Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access toapache · cloudstack · CWE-359 | High8.1 | — | 0.5% | May 8, 2026 |
32Monitor | CVE-2025-11959No exploit | Improper Access Control in Premierturk's Excavation Management Information Systempremierturk information technologies inc. · excavation management information system · CWE-359 | High8.1 | — | 0.3% | Nov 11, 2025 |
30Monitor | CVE-2021-3980No exploit | Exposure of Private Personal Information to an Unauthorized Actor in elgg/elggelgg · elgg · CWE-359 | High7.5 | — | 1.6% | Dec 3, 2021 |
- CVE-2022-048249Plan
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
CriticalCVSS 9.1Proof of conceptEPSS 44%easyappointments · easyappointmentsMar 9, 2022
- CVE-2023-3605240Plan
Azure CLI REST Command Information Disclosure Vulnerability
HighCVSS 8.6No exploitEPSS 21%microsoft · azure command-line interfaceNov 14, 2023
- CVE-2023-3601839Monitor
Visual Studio Code Jupyter Extension Spoofing Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%microsoft · jupyterNov 14, 2023
- CVE-2025-1562337Monitor
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
CriticalCVSS 9.3No exploitEPSS 0%sparxsystems · pro cloud serverApr 17, 2026
- CVE-2024-4976536Monitor
Bypass of Discourse Connect using other login paths if enabled in Discourse
CriticalCVSS 9.1No exploitEPSS 0%discourse · discourseDec 19, 2024
- CVE-2022-292135Monitor
Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserp
HighCVSS 8.8No exploitEPSS 1%notrinos · notrinoserpAug 21, 2022
- CVE-2025-5412534Monitor
XWiki Platform: Password and email exposure in xml.vm fields
HighCVSS 8.7Proof of conceptEPSS 1%xwiki · xwikiAug 5, 2025
- CVE-2019-2576234Monitor
Joomla! Component JoomProject 1.1.3.2 Information Disclosure
HighCVSS 8.7No exploitEPSS 1%joomboost · joomprojectJun 19, 2026
- CVE-2026-5612434Monitor
phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
HighCVSS 8.7No exploitEPSS 1%shimosyan · phpuploaderJun 29, 2026
- CVE-2026-6232834Monitor
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
HighCVSS 8.7No exploitEPSS 1%decolua · 9routerJul 13, 2026
- CVE-2020-3717334Monitor
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
HighCVSS 8.7No exploitEPSS 1%wwbn · avideoFeb 11, 2026
- CVE-2025-1300834Monitor
Session Token Disclosure in M-Files Web
HighCVSS 8.6No exploitEPSS 0%m-files corporation · m-files serverDec 19, 2025
- CVE-2025-5362534Monitor
DynamicPageList3 exposes hidden/suppressed usernames
HighCVSS 8.7No exploitEPSS 0%universal-omega · dynamicpagelist3Jul 10, 2025
- CVE-2024-4708534Monitor
Parameter Manipulation Vulnerability
HighCVSS 8.7No exploitEPSS 0%apexsoftcell · ld geoSep 19, 2024
- CVE-2024-4708734Monitor
Information Disclosure Vulnerability
HighCVSS 8.7No exploitEPSS 0%apexsoftcell · ld geoSep 19, 2024
- CVE-2024-4578734Monitor
Information Disclosure Vulnerability
HighCVSS 8.7No exploitEPSS 0%reedos · aim-starSep 11, 2024
- CVE-2025-2006034Monitor
Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actor
HighCVSS 8.7No exploitEPSS 0%dario health · usb-c blood glucose monitoring system starter kit android applicationsFeb 28, 2025
- CVE-2026-5796033Monitor
Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id
HighCVSS 8.3No exploitEPSS 0%hieventsdev · hi.eventsJun 29, 2026
- CVE-2025-1045033Monitor
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.
HighCVSS 8.3No exploitEPSS 0%rti · connext professionalDec 16, 2025
- CVE-2024-2619232Monitor
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
HighCVSS 8.2No exploitEPSS 2%microsoft · edge chromiumFeb 23, 2024
- CVE-2025-068332Monitor
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitor
HighCVSS 8.2No exploitEPSS 1%contec health · cms8000 patient monitorJan 30, 2025
- CVE-2024-3032132Monitor
A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versio
HighCVSS 8.2No exploitEPSS 1%siemens · simatic pcs 7 v9.1Jul 9, 2024
- CVE-2025-6617232Monitor
Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
HighCVSS 8.1No exploitEPSS 1%apache · cloudstackMay 8, 2026
- CVE-2025-1195932Monitor
Improper Access Control in Premierturk's Excavation Management Information System
HighCVSS 8.1No exploitEPSS 0%premierturk information technologies inc. · excavation management information systemNov 11, 2025
- CVE-2021-398030Monitor
Exposure of Private Personal Information to an Unauthorized Actor in elgg/elgg
HighCVSS 7.5No exploitEPSS 2%elgg · elggDec 3, 2021