CWE-213 · 32 записей
Exposure of Sensitive Information Due to Incompatible Policies
CVE этого класса
32 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-1652Эксплойта нет | Junos Space: OpenNMS is accessible via port 9443opennms · opennms · CWE-213 | Критическая9,8 | — | 0,7 % | 17 июл. 2020 г. |
36Наблюдать | CVE-2023-3441Эксплойта нет | Exposure of Sensitive Information Due to Incompatible Policies in GitLabgitlab · gitlab · CWE-213 | Критическая9,1 | — | 0,6 % | 1 окт. 2024 г. |
30Наблюдать | CVE-2019-1010283Эксплойта нет | Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure.univention · univention corporate server · CWE-213 | Высокая7,5 | — | 1,4 % | 17 июл. 2019 г. |
30Наблюдать | CVE-2022-30350Эксплойта нет | Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure.avanquest · pdfescape · CWE-213 | Высокая7,5 | — | 0,7 % | 30 мар. 2023 г. |
30Наблюдать | CVE-2023-6517Эксплойта нет | Seeing the SMS Verification Code in Mia Technology's Mia-Medmiateknoloji · mia-med · CWE-213 | Высокая7,5 | — | 0,5 % | 8 февр. 2024 г. |
30Наблюдать | CVE-2024-49354Эксплойта нет | IBM Concert information disclosureibm · concert · CWE-213 | Высокая7,5 | — | 0,3 % | 18 янв. 2025 г. |
30Наблюдать | CVE-2024-49827Эксплойта нет | IBM Concert Software information disclosureibm · concert · CWE-213 | Высокая7,5 | — | 0,2 % | 18 авг. 2025 г. |
28Наблюдать | CVE-2024-7267Эксплойта нет | Internal infrastructure data leak in EZD RPnask · ezd rp · CWE-213 | Высокая7,1 | — | 0,6 % | 7 авг. 2024 г. |
27Наблюдать | CVE-2025-24316Эксплойта нет | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policiesdario health · dario application database and internet-based server infrastructure · CWE-213 | Средняя6,9 | — | 0,3 % | 28 февр. 2025 г. |
26Наблюдать | CVE-2025-54831Эксплойта нет | Apache Airflow: Connection sensitive details exposed to users with READ permissionsapache · airflow · CWE-213 | Средняя6,5 | — | 0,9 % | 26 сент. 2025 г. |
26Наблюдать | CVE-2022-22541Эксплойта нет | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see sap · businessobjects business intelligence platform · CWE-213 | Средняя6,5 | — | 0,8 % | 12 апр. 2022 г. |
26Наблюдать | CVE-2026-6280Эксплойта нет | Improper Access Control in Nomysoft Informatics' Nomysemnomysoft informatics education and consulting inc. · nomysem · CWE-213 | Средняя6,5 | — | 0,4 % | 8 июл. 2026 г. |
23Наблюдать | CVE-2019-10247Эксплойта нет | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version eclipse · jetty · CWE-213 | Средняя5,3 | — | 5,9 % | 22 апр. 2019 г. |
22Наблюдать | CVE-2019-10246Эксплойта нет | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Reseclipse · jetty · CWE-213 | Средняя5,3 | — | 4,1 % | 22 апр. 2019 г. |
21Наблюдать | CVE-2017-3211Эксплойта нет | Centire Yopify leaks customer informationyopify · yopify · CWE-213 | Средняя5,3 | — | 0,8 % | 15 янв. 2020 г. |
21Наблюдать | CVE-2023-40570Эксплойта нет | Datasette 1.0 alpha series leaks names of databases and tables to unauthenticated usersdatasette · datasette · CWE-213 | Средняя5,3 | — | 0,6 % | 24 авг. 2023 г. |
21Наблюдать | CVE-2023-36919Эксплойта нет | Information Disclosure in SAP Enable Nowsap · enable now · CWE-213 | Средняя5,3 | — | 0,5 % | 10 июл. 2023 г. |
21Наблюдать | CVE-2025-4976Эксплойта нет | Exposure of Sensitive Information Due to Incompatible Policies in GitLabgitlab · gitlab · CWE-213 | Средняя5,3 | — | 0,4 % | 24 июл. 2025 г. |
20Наблюдать | CVE-2026-55425Эксплойта нет | Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fieldsgraylog2 · graylog2-server · CWE-213 | Средняя5,0 | — | 0,4 % | 28 авг. 2026 г. |
18Наблюдать | CVE-2023-27465Эксплойта нет | A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1), siemens · simotion d425-2 dp firmware · CWE-213 | Средняя4,6 | — | 0,3 % | 13 июн. 2023 г. |
17Наблюдать | CVE-2024-44121Эксплойта нет | Information Disclosure in SAP S/4 HANA (Statutory Reports)sap_se · sap s/4 hana (statutory reports) · CWE-213 | Средняя4,3 | — | 0,3 % | 10 сент. 2024 г. |
17Наблюдать | CVE-2025-32791Эксплойта нет | Permission policy information leakage in Backstage permission systembackstage · backstage · CWE-213 | Средняя4,3 | — | 0,3 % | 16 апр. 2025 г. |
14Наблюдать | CVE-2023-5117Эксплойта нет | Exposure of Sensitive Information Due to Incompatible Policies in GitLabgitlab · gitlab · CWE-213 | Низкая3,7 | — | 0,3 % | 25 дек. 2024 г. |
14Наблюдать | CVE-2026-56538Эксплойта нет | HCL Connections is vulnerable to information disclosurehcltech · connections · CWE-213 | Низкая3,5 | — | 0,3 % | 27 июл. 2026 г. |
14Наблюдать | CVE-2025-52603Эксплойта нет | HCL Connections is vulnerable to information disclosurehcltech · connections · CWE-213 | Низкая3,5 | — | 0,3 % | 20 февр. 2026 г. |
- CVE-2020-165239Наблюдать
Junos Space: OpenNMS is accessible via port 9443
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %opennms · opennms17 июл. 2020 г.
- CVE-2023-344136Наблюдать
Exposure of Sensitive Information Due to Incompatible Policies in GitLab
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %gitlab · gitlab1 окт. 2024 г.
- CVE-2019-101028330Наблюдать
Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %univention · univention corporate server17 июл. 2019 г.
- CVE-2022-3035030Наблюдать
Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %avanquest · pdfescape30 мар. 2023 г.
- CVE-2023-651730Наблюдать
Seeing the SMS Verification Code in Mia Technology's Mia-Med
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %miateknoloji · mia-med8 февр. 2024 г.
- CVE-2024-4935430Наблюдать
IBM Concert information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · concert18 янв. 2025 г.
- CVE-2024-4982730Наблюдать
IBM Concert Software information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · concert18 авг. 2025 г.
- CVE-2024-726728Наблюдать
Internal infrastructure data leak in EZD RP
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %nask · ezd rp7 авг. 2024 г.
- CVE-2025-2431627Наблюдать
Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policies
СредняяCVSS 6,9Эксплойта нетEPSS 0 %dario health · dario application database and internet-based server infrastructure28 февр. 2025 г.
- CVE-2025-5483126Наблюдать
Apache Airflow: Connection sensitive details exposed to users with READ permissions
СредняяCVSS 6,5Эксплойта нетEPSS 1 %apache · airflow26 сент. 2025 г.
- CVE-2022-2254126Наблюдать
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see
СредняяCVSS 6,5Эксплойта нетEPSS 1 %sap · businessobjects business intelligence platform12 апр. 2022 г.
- CVE-2026-628026Наблюдать
Improper Access Control in Nomysoft Informatics' Nomysem
СредняяCVSS 6,5Эксплойта нетEPSS 0 %nomysoft informatics education and consulting inc. · nomysem8 июл. 2026 г.
- CVE-2019-1024723Наблюдать
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version
СредняяCVSS 5,3Эксплойта нетEPSS 6 %eclipse · jetty22 апр. 2019 г.
- CVE-2019-1024622Наблюдать
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Res
СредняяCVSS 5,3Эксплойта нетEPSS 4 %eclipse · jetty22 апр. 2019 г.
- CVE-2017-321121Наблюдать
Centire Yopify leaks customer information
СредняяCVSS 5,3Эксплойта нетEPSS 1 %yopify · yopify15 янв. 2020 г.
- CVE-2023-4057021Наблюдать
Datasette 1.0 alpha series leaks names of databases and tables to unauthenticated users
СредняяCVSS 5,3Эксплойта нетEPSS 1 %datasette · datasette24 авг. 2023 г.
- CVE-2023-3691921Наблюдать
Information Disclosure in SAP Enable Now
СредняяCVSS 5,3Эксплойта нетEPSS 0 %sap · enable now10 июл. 2023 г.
- CVE-2025-497621Наблюдать
Exposure of Sensitive Information Due to Incompatible Policies in GitLab
СредняяCVSS 5,3Эксплойта нетEPSS 0 %gitlab · gitlab24 июл. 2025 г.
- CVE-2026-5542520Наблюдать
Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields
СредняяCVSS 5,0Эксплойта нетEPSS 0 %graylog2 · graylog2-server28 авг. 2026 г.
- CVE-2023-2746518Наблюдать
A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1),
СредняяCVSS 4,6Эксплойта нетEPSS 0 %siemens · simotion d425-2 dp firmware13 июн. 2023 г.
- CVE-2024-4412117Наблюдать
Information Disclosure in SAP S/4 HANA (Statutory Reports)
СредняяCVSS 4,3Эксплойта нетEPSS 0 %sap_se · sap s/4 hana (statutory reports)10 сент. 2024 г.
- CVE-2025-3279117Наблюдать
Permission policy information leakage in Backstage permission system
СредняяCVSS 4,3Эксплойта нетEPSS 0 %backstage · backstage16 апр. 2025 г.
- CVE-2023-511714Наблюдать
Exposure of Sensitive Information Due to Incompatible Policies in GitLab
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %gitlab · gitlab25 дек. 2024 г.
- CVE-2026-5653814Наблюдать
HCL Connections is vulnerable to information disclosure
НизкаяCVSS 3,5Эксплойта нетEPSS 0 %hcltech · connections27 июл. 2026 г.
- CVE-2025-5260314Наблюдать
HCL Connections is vulnerable to information disclosure
НизкаяCVSS 3,5Эксплойта нетEPSS 0 %hcltech · connections20 февр. 2026 г.