CWE-202 · 34 записей
Exposure of Sensitive Information Through Data Queries
CVE этого класса
34 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2021-32743Эксплойта нет | Passwords used to access external services inadvertently exposed through APIicinga · icinga · CWE-202 | Высокая8,8 | — | 1,8 % | 15 июл. 2021 г. |
33Наблюдать | CVE-2025-25205Готовый эксплойт | Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matchingaudiobookshelf · audiobookshelf · CWE-202 | Высокая8,2 | — | 4,8 % | 12 февр. 2025 г. |
32Наблюдать | CVE-2024-6400Эксплойта нет | Cleartext Storage of Username and Password in Finrota's Netahsilatfinrota · finrota · CWE-202 | Высокая8,2 | — | 0,6 % | 4 окт. 2024 г. |
31Наблюдать | CVE-2025-69200Proof of concept | phpMyFAQ has unauthenticated config backup download via /api/setup/backupphpmyfaq · phpmyfaq · CWE-202 | Высокая7,5 | — | 2,1 % | 29 дек. 2025 г. |
30Наблюдать | CVE-2022-41623Эксплойта нет | WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerabilityvillatheme · dropshipping and fulfillment for aliexpress and woocommerce · CWE-202 | Высокая7,5 | — | 0,8 % | 14 окт. 2022 г. |
30Наблюдать | CVE-2023-7072Эксплойта нет | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpointpickplugins · post grid combo · CWE-202 | Высокая7,5 | — | 0,6 % | 12 мар. 2024 г. |
30Наблюдать | CVE-2026-30778Эксплойта нет | Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.apache · skywalking · CWE-202 | Высокая7,5 | — | 0,6 % | 15 апр. 2026 г. |
30Наблюдать | CVE-2024-13255Эксплойта нет | RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019restful web services project · restful web services · CWE-202 | Высокая7,5 | — | 0,5 % | 9 янв. 2025 г. |
30Наблюдать | CVE-2025-29981Эксплойта нет | Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.dell · wyse management suite · CWE-202 | Высокая7,5 | — | 0,4 % | 1 апр. 2025 г. |
30Наблюдать | CVE-2025-36575Эксплойта нет | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.dell · wyse management suite · CWE-202 | Высокая7,5 | — | 0,3 % | 10 июн. 2025 г. |
29Наблюдать | CVE-2026-25703Proof of concept | Potential information leakage from manager /network/graph API in NeuVectorsuse · neuvector · CWE-202 | Высокая7,3 | — | 0,8 % | 5 авг. 2026 г. |
28Наблюдать | CVE-2025-68456Эксплойта нет | Unauthenticated Craft CMS users can trigger a database backupcraftcms · craft cms · CWE-202 | Высокая7,0 | — | 0,5 % | 5 янв. 2026 г. |
26Наблюдать | CVE-2022-20747Эксплойта нет | Cisco SD-WAN vManage Software Information Disclosure Vulnerabilitycisco · catalyst sd-wan manager · CWE-202 | Средняя6,5 | — | 0,9 % | 15 апр. 2022 г. |
26Наблюдать | CVE-2022-20810Эксплойта нет | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerabilitycisco · ios xe · CWE-202 | Средняя6,5 | — | 0,8 % | 30 сент. 2022 г. |
26Наблюдать | CVE-2024-1287Эксплойта нет | Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQListrangerstudios · paid memberships pro · CWE-202 | Средняя6,5 | — | 0,5 % | 30 июл. 2024 г. |
26Наблюдать | CVE-2024-38892Эксплойта нет | An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.wavlink · wn551k1 firmware · CWE-202 | Средняя6,5 | — | 0,4 % | 24 июн. 2024 г. |
26Наблюдать | CVE-2024-2088Эксплойта нет | NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposurenextscripts · social networks auto poster · CWE-202 | Средняя6,5 | — | 0,3 % | 22 мая 2024 г. |
26Наблюдать | CVE-2026-33530Эксплойта нет | InvenTree Vulnerable to ORM Filter Injectioninventree project · inventree · CWE-202 | Средняя6,5 | — | 0,3 % | 26 мар. 2026 г. |
25Наблюдать | CVE-2025-64528Эксплойта нет | Users are able to find users by name even when `enable_names` is offdiscourse · discourse · CWE-202 | Средняя6,3 | — | 0,3 % | 30 дек. 2025 г. |
22Наблюдать | CVE-2021-1372Эксплойта нет | Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerabilitycisco · webex meetings · CWE-202 | Средняя5,5 | — | 0,4 % | 17 февр. 2021 г. |
21Наблюдать | CVE-2023-20215Эксплойта нет | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacisco · asyncos · CWE-202 | Средняя5,3 | — | 0,6 % | 3 авг. 2023 г. |
21Наблюдать | CVE-2024-20388Эксплойта нет | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote atcisco · firepower management center · CWE-202 | Средняя5,3 | — | 0,4 % | 23 окт. 2024 г. |
21Наблюдать | CVE-2024-38897Эксплойта нет | WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.wavlink · wn551k1 firmware · CWE-202 | Средняя5,3 | — | 0,4 % | 24 июн. 2024 г. |
21Наблюдать | CVE-2026-3546Эксплойта нет | e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJforfront · e-shot · CWE-202 | Средняя5,3 | — | 0,4 % | 21 мар. 2026 г. |
21Наблюдать | CVE-2024-38895Эксплойта нет | WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.wavlink · wn551k1 firmware · CWE-202 | Средняя5,3 | — | 0,4 % | 24 июн. 2024 г. |
- CVE-2021-3274336Наблюдать
Passwords used to access external services inadvertently exposed through API
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %icinga · icinga15 июл. 2021 г.
- CVE-2025-2520533Наблюдать
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
ВысокаяCVSS 8,2Готовый эксплойтEPSS 5 %audiobookshelf · audiobookshelf12 февр. 2025 г.
- CVE-2024-640032Наблюдать
Cleartext Storage of Username and Password in Finrota's Netahsilat
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %finrota · finrota4 окт. 2024 г.
- CVE-2025-6920031Наблюдать
phpMyFAQ has unauthenticated config backup download via /api/setup/backup
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %phpmyfaq · phpmyfaq29 дек. 2025 г.
- CVE-2022-4162330Наблюдать
WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %villatheme · dropshipping and fulfillment for aliexpress and woocommerce14 окт. 2022 г.
- CVE-2023-707230Наблюдать
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pickplugins · post grid combo12 мар. 2024 г.
- CVE-2026-3077830Наблюдать
Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apache · skywalking15 апр. 2026 г.
- CVE-2024-1325530Наблюдать
RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %restful web services project · restful web services9 янв. 2025 г.
- CVE-2025-2998130Наблюдать
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dell · wyse management suite1 апр. 2025 г.
- CVE-2025-3657530Наблюдать
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %dell · wyse management suite10 июн. 2025 г.
- CVE-2026-2570329Наблюдать
Potential information leakage from manager /network/graph API in NeuVector
ВысокаяCVSS 7,3Proof of conceptEPSS 1 %suse · neuvector5 авг. 2026 г.
- CVE-2025-6845628Наблюдать
Unauthenticated Craft CMS users can trigger a database backup
ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %craftcms · craft cms5 янв. 2026 г.
- CVE-2022-2074726Наблюдать
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cisco · catalyst sd-wan manager15 апр. 2022 г.
- CVE-2022-2081026Наблюдать
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cisco · ios xe30 сент. 2022 г.
- CVE-2024-128726Наблюдать
Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi
СредняяCVSS 6,5Эксплойта нетEPSS 1 %strangerstudios · paid memberships pro30 июл. 2024 г.
- CVE-2024-3889226Наблюдать
An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %wavlink · wn551k1 firmware24 июн. 2024 г.
- CVE-2024-208826Наблюдать
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure
СредняяCVSS 6,5Эксплойта нетEPSS 0 %nextscripts · social networks auto poster22 мая 2024 г.
- CVE-2026-3353026Наблюдать
InvenTree Vulnerable to ORM Filter Injection
СредняяCVSS 6,5Эксплойта нетEPSS 0 %inventree project · inventree26 мар. 2026 г.
- CVE-2025-6452825Наблюдать
Users are able to find users by name even when `enable_names` is off
СредняяCVSS 6,3Эксплойта нетEPSS 0 %discourse · discourse30 дек. 2025 г.
- CVE-2021-137222Наблюдать
Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability
СредняяCVSS 5,5Эксплойта нетEPSS 0 %cisco · webex meetings17 февр. 2021 г.
- CVE-2023-2021521Наблюдать
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote atta
СредняяCVSS 5,3Эксплойта нетEPSS 1 %cisco · asyncos3 авг. 2023 г.
- CVE-2024-2038821Наблюдать
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote at
СредняяCVSS 5,3Эксплойта нетEPSS 0 %cisco · firepower management center23 окт. 2024 г.
- CVE-2024-3889721Наблюдать
WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %wavlink · wn551k1 firmware24 июн. 2024 г.
- CVE-2026-354621Наблюдать
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJ
СредняяCVSS 5,3Эксплойта нетEPSS 0 %forfront · e-shot21 мар. 2026 г.
- CVE-2024-3889521Наблюдать
WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %wavlink · wn551k1 firmware24 июн. 2024 г.