CWE-359 · 191 записей
Exposure of Private Personal Information to an Unauthorized Actor
CVE этого класса
192 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2022-0482Proof of concept | Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-359 | Критическая9,1 | — | 43,7 % | 9 мар. 2022 г. |
40В плане | CVE-2023-36052Эксплойта нет | Azure CLI REST Command Information Disclosure Vulnerabilitymicrosoft · azure command-line interface · CWE-359 | Высокая8,6 | — | 21,1 % | 14 нояб. 2023 г. |
39Наблюдать | CVE-2023-36018Эксплойта нет | Visual Studio Code Jupyter Extension Spoofing Vulnerabilitymicrosoft · jupyter · CWE-359 | Критическая9,8 | — | 1,5 % | 14 нояб. 2023 г. |
37Наблюдать | CVE-2025-15623Эксплойта нет | Sparx Pro Cloud Server reveals sensitive information to an unauthenticated usersparxsystems · pro cloud server · CWE-359 | Критическая9,3 | — | 0,3 % | 17 апр. 2026 г. |
36Наблюдать | CVE-2024-49765Эксплойта нет | Bypass of Discourse Connect using other login paths if enabled in Discoursediscourse · discourse · CWE-359 | Критическая9,1 | — | 0,4 % | 19 дек. 2024 г. |
35Наблюдать | CVE-2022-2921Эксплойта нет | Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserpnotrinos · notrinoserp · CWE-359 | Высокая8,8 | — | 1,3 % | 21 авг. 2022 г. |
34Наблюдать | CVE-2025-54125Proof of concept | XWiki Platform: Password and email exposure in xml.vm fieldsxwiki · xwiki · CWE-359 | Высокая8,7 | — | 1,3 % | 5 авг. 2025 г. |
34Наблюдать | CVE-2019-25762Эксплойта нет | Joomla! Component JoomProject 1.1.3.2 Information Disclosurejoomboost · joomproject · CWE-359 | Высокая8,7 | — | 0,7 % | 19 июн. 2026 г. |
34Наблюдать | CVE-2026-56124Эксплойта нет | phpUploader < 2.0.2 Unauthenticated Database Exposure via index modelshimosyan · phpuploader · CWE-359 | Высокая8,7 | — | 0,6 % | 29 июн. 2026 г. |
34Наблюдать | CVE-2026-62328Эксплойта нет | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpointsdecolua · 9router · CWE-359 | Высокая8,7 | — | 0,6 % | 13 июл. 2026 г. |
34Наблюдать | CVE-2020-37173Эксплойта нет | AVideo Platform 8.1 - Information Disclosure (User Enumeration)wwbn · avideo · CWE-359 | Высокая8,7 | — | 0,6 % | 11 февр. 2026 г. |
34Наблюдать | CVE-2025-13008Эксплойта нет | Session Token Disclosure in M-Files Webm-files corporation · m-files server · CWE-359 | Высокая8,6 | — | 0,5 % | 19 дек. 2025 г. |
34Наблюдать | CVE-2025-53625Эксплойта нет | DynamicPageList3 exposes hidden/suppressed usernamesuniversal-omega · dynamicpagelist3 · CWE-359 | Высокая8,7 | — | 0,4 % | 10 июл. 2025 г. |
34Наблюдать | CVE-2024-45787Эксплойта нет | Information Disclosure Vulnerabilityreedos · aim-star · CWE-359 | Высокая8,7 | — | 0,4 % | 11 сент. 2024 г. |
34Наблюдать | CVE-2024-47087Эксплойта нет | Information Disclosure Vulnerabilityapexsoftcell · ld geo · CWE-359 | Высокая8,7 | — | 0,4 % | 19 сент. 2024 г. |
34Наблюдать | CVE-2024-47085Эксплойта нет | Parameter Manipulation Vulnerabilityapexsoftcell · ld geo · CWE-359 | Высокая8,7 | — | 0,4 % | 19 сент. 2024 г. |
34Наблюдать | CVE-2025-20060Эксплойта нет | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actordario health · usb-c blood glucose monitoring system starter kit android applications · CWE-359 | Высокая8,7 | — | 0,4 % | 28 февр. 2025 г. |
33Наблюдать | CVE-2026-57960Эксплойта нет | Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_idhieventsdev · hi.events · CWE-359 | Высокая8,3 | — | 0,4 % | 29 июн. 2026 г. |
33Наблюдать | CVE-2025-10450Эксплойта нет | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.rti · connext professional · CWE-359 | Высокая8,3 | — | 0,2 % | 16 дек. 2025 г. |
32Наблюдать | CVE-2024-26192Эксплойта нет | Microsoft Edge (Chromium-based) Information Disclosure Vulnerabilitymicrosoft · edge chromium · CWE-359 | Высокая8,2 | — | 1,5 % | 23 февр. 2024 г. |
32Наблюдать | CVE-2025-0683Эксплойта нет | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitorcontec health · cms8000 patient monitor · CWE-359 | Высокая8,2 | — | 0,8 % | 30 янв. 2025 г. |
32Наблюдать | CVE-2024-30321Эксплойта нет | A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versiosiemens · simatic pcs 7 v9.1 · CWE-359 | Высокая8,2 | — | 0,5 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2025-66172Эксплойта нет | Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access toapache · cloudstack · CWE-359 | Высокая8,1 | — | 0,5 % | 8 мая 2026 г. |
32Наблюдать | CVE-2025-11959Эксплойта нет | Improper Access Control in Premierturk's Excavation Management Information Systempremierturk information technologies inc. · excavation management information system · CWE-359 | Высокая8,1 | — | 0,3 % | 11 нояб. 2025 г. |
30Наблюдать | CVE-2021-3980Эксплойта нет | Exposure of Private Personal Information to an Unauthorized Actor in elgg/elggelgg · elgg · CWE-359 | Высокая7,5 | — | 1,6 % | 3 дек. 2021 г. |
- CVE-2022-048249В плане
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
КритическаяCVSS 9,1Proof of conceptEPSS 44 %easyappointments · easyappointments9 мар. 2022 г.
- CVE-2023-3605240В плане
Azure CLI REST Command Information Disclosure Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 21 %microsoft · azure command-line interface14 нояб. 2023 г.
- CVE-2023-3601839Наблюдать
Visual Studio Code Jupyter Extension Spoofing Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microsoft · jupyter14 нояб. 2023 г.
- CVE-2025-1562337Наблюдать
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %sparxsystems · pro cloud server17 апр. 2026 г.
- CVE-2024-4976536Наблюдать
Bypass of Discourse Connect using other login paths if enabled in Discourse
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %discourse · discourse19 дек. 2024 г.
- CVE-2022-292135Наблюдать
Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserp
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %notrinos · notrinoserp21 авг. 2022 г.
- CVE-2025-5412534Наблюдать
XWiki Platform: Password and email exposure in xml.vm fields
ВысокаяCVSS 8,7Proof of conceptEPSS 1 %xwiki · xwiki5 авг. 2025 г.
- CVE-2019-2576234Наблюдать
Joomla! Component JoomProject 1.1.3.2 Information Disclosure
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %joomboost · joomproject19 июн. 2026 г.
- CVE-2026-5612434Наблюдать
phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %shimosyan · phpuploader29 июн. 2026 г.
- CVE-2026-6232834Наблюдать
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %decolua · 9router13 июл. 2026 г.
- CVE-2020-3717334Наблюдать
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %wwbn · avideo11 февр. 2026 г.
- CVE-2025-1300834Наблюдать
Session Token Disclosure in M-Files Web
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %m-files corporation · m-files server19 дек. 2025 г.
- CVE-2025-5362534Наблюдать
DynamicPageList3 exposes hidden/suppressed usernames
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %universal-omega · dynamicpagelist310 июл. 2025 г.
- CVE-2024-4578734Наблюдать
Information Disclosure Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %reedos · aim-star11 сент. 2024 г.
- CVE-2024-4708734Наблюдать
Information Disclosure Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %apexsoftcell · ld geo19 сент. 2024 г.
- CVE-2024-4708534Наблюдать
Parameter Manipulation Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %apexsoftcell · ld geo19 сент. 2024 г.
- CVE-2025-2006034Наблюдать
Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actor
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %dario health · usb-c blood glucose monitoring system starter kit android applications28 февр. 2025 г.
- CVE-2026-5796033Наблюдать
Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %hieventsdev · hi.events29 июн. 2026 г.
- CVE-2025-1045033Наблюдать
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %rti · connext professional16 дек. 2025 г.
- CVE-2024-2619232Наблюдать
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
ВысокаяCVSS 8,2Эксплойта нетEPSS 2 %microsoft · edge chromium23 февр. 2024 г.
- CVE-2025-068332Наблюдать
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitor
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %contec health · cms8000 patient monitor30 янв. 2025 г.
- CVE-2024-3032132Наблюдать
A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versio
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %siemens · simatic pcs 7 v9.19 июл. 2024 г.
- CVE-2025-6617232Наблюдать
Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %apache · cloudstack8 мая 2026 г.
- CVE-2025-1195932Наблюдать
Improper Access Control in Premierturk's Excavation Management Information System
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %premierturk information technologies inc. · excavation management information system11 нояб. 2025 г.
- CVE-2021-398030Наблюдать
Exposure of Private Personal Information to an Unauthorized Actor in elgg/elgg
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %elgg · elgg3 дек. 2021 г.