Перейти к содержимому
Noroxi

CWE-202 · 34 записей

Exposure of Sensitive Information Through Data Queries

CVE этого класса

34 записей

  • CVE-2021-32743
    36Наблюдать

    Passwords used to access external services inadvertently exposed through API

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    icinga · icinga15 июл. 2021 г.

  • CVE-2025-25205
    33Наблюдать

    Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching

    ВысокаяCVSS 8,2Готовый эксплойтEPSS 5 %

    audiobookshelf · audiobookshelf12 февр. 2025 г.

  • CVE-2024-6400
    32Наблюдать

    Cleartext Storage of Username and Password in Finrota's Netahsilat

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    finrota · finrota4 окт. 2024 г.

  • CVE-2025-69200
    31Наблюдать

    phpMyFAQ has unauthenticated config backup download via /api/setup/backup

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    phpmyfaq · phpmyfaq29 дек. 2025 г.

  • CVE-2022-41623
    30Наблюдать

    WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerability

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    villatheme · dropshipping and fulfillment for aliexpress and woocommerce14 окт. 2022 г.

  • CVE-2023-7072
    30Наблюдать

    Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    pickplugins · post grid combo12 мар. 2024 г.

  • CVE-2026-30778
    30Наблюдать

    Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    apache · skywalking15 апр. 2026 г.

  • CVE-2024-13255
    30Наблюдать

    RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    restful web services project · restful web services9 янв. 2025 г.

  • CVE-2025-29981
    30Наблюдать

    Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    dell · wyse management suite1 апр. 2025 г.

  • CVE-2025-36575
    30Наблюдать

    Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    dell · wyse management suite10 июн. 2025 г.

  • CVE-2026-25703
    29Наблюдать

    Potential information leakage from manager /network/graph API in NeuVector

    ВысокаяCVSS 7,3Proof of conceptEPSS 1 %

    suse · neuvector5 авг. 2026 г.

  • CVE-2025-68456
    28Наблюдать

    Unauthenticated Craft CMS users can trigger a database backup

    ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %

    craftcms · craft cms5 янв. 2026 г.

  • CVE-2022-20747
    26Наблюдать

    Cisco SD-WAN vManage Software Information Disclosure Vulnerability

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    cisco · catalyst sd-wan manager15 апр. 2022 г.

  • CVE-2022-20810
    26Наблюдать

    Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerability

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    cisco · ios xe30 сент. 2022 г.

  • CVE-2024-1287
    26Наблюдать

    Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    strangerstudios · paid memberships pro30 июл. 2024 г.

  • CVE-2024-38892
    26Наблюдать

    An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    wavlink · wn551k1 firmware24 июн. 2024 г.

  • CVE-2024-2088
    26Наблюдать

    NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    nextscripts · social networks auto poster22 мая 2024 г.

  • CVE-2026-33530
    26Наблюдать

    InvenTree Vulnerable to ORM Filter Injection

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    inventree project · inventree26 мар. 2026 г.

  • CVE-2025-64528
    25Наблюдать

    Users are able to find users by name even when `enable_names` is off

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    discourse · discourse30 дек. 2025 г.

  • CVE-2021-1372
    22Наблюдать

    Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    cisco · webex meetings17 февр. 2021 г.

  • CVE-2023-20215
    21Наблюдать

    A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote atta

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    cisco · asyncos3 авг. 2023 г.

  • CVE-2024-20388
    21Наблюдать

    A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote at

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    cisco · firepower management center23 окт. 2024 г.

  • CVE-2024-38897
    21Наблюдать

    WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    wavlink · wn551k1 firmware24 июн. 2024 г.

  • CVE-2026-3546
    21Наблюдать

    e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJ

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    forfront · e-shot21 мар. 2026 г.

  • CVE-2024-38895
    21Наблюдать

    WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    wavlink · wn551k1 firmware24 июн. 2024 г.

Все классы уязвимостей