İçeriğe atla
Noroxi

CWE-202 · 34 kayıt

Exposure of Sensitive Information Through Data Queries

Bu sınıftaki CVE’ler

34 kayıt

  • CVE-2021-32743
    36İzleyin

    Passwords used to access external services inadvertently exposed through API

    YüksekCVSS 8,8İstismar yokEPSS %2

    icinga · icinga15 Tem 2021

  • CVE-2025-25205
    33İzleyin

    Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching

    YüksekCVSS 8,2SilahlaştırılmışEPSS %5

    audiobookshelf · audiobookshelf12 Şub 2025

  • CVE-2024-6400
    32İzleyin

    Cleartext Storage of Username and Password in Finrota's Netahsilat

    YüksekCVSS 8,2İstismar yokEPSS %1

    finrota · finrota4 Eki 2024

  • CVE-2025-69200
    31İzleyin

    phpMyFAQ has unauthenticated config backup download via /api/setup/backup

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    phpmyfaq · phpmyfaq29 Ara 2025

  • CVE-2022-41623
    30İzleyin

    WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    villatheme · dropshipping and fulfillment for aliexpress and woocommerce14 Eki 2022

  • CVE-2023-7072
    30İzleyin

    Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint

    YüksekCVSS 7,5İstismar yokEPSS %1

    pickplugins · post grid combo12 Mar 2024

  • CVE-2026-30778
    30İzleyin

    Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.

    YüksekCVSS 7,5İstismar yokEPSS %1

    apache · skywalking15 Nis 2026

  • CVE-2024-13255
    30İzleyin

    RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019

    YüksekCVSS 7,5İstismar yokEPSS %1

    restful web services project · restful web services9 Oca 2025

  • CVE-2025-29981
    30İzleyin

    Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.

    YüksekCVSS 7,5İstismar yokEPSS %0

    dell · wyse management suite1 Nis 2025

  • CVE-2025-36575
    30İzleyin

    Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.

    YüksekCVSS 7,5İstismar yokEPSS %0

    dell · wyse management suite10 Haz 2025

  • CVE-2026-25703
    29İzleyin

    Potential information leakage from manager /network/graph API in NeuVector

    YüksekCVSS 7,3Kavram kanıtıEPSS %1

    suse · neuvector5 Ağu 2026

  • CVE-2025-68456
    28İzleyin

    Unauthenticated Craft CMS users can trigger a database backup

    YüksekCVSS 7,0İstismar yokEPSS %1

    craftcms · craft cms5 Oca 2026

  • CVE-2022-20747
    26İzleyin

    Cisco SD-WAN vManage Software Information Disclosure Vulnerability

    OrtaCVSS 6,5İstismar yokEPSS %1

    cisco · catalyst sd-wan manager15 Nis 2022

  • CVE-2022-20810
    26İzleyin

    Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerability

    OrtaCVSS 6,5İstismar yokEPSS %1

    cisco · ios xe30 Eyl 2022

  • CVE-2024-1287
    26İzleyin

    Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi

    OrtaCVSS 6,5İstismar yokEPSS %1

    strangerstudios · paid memberships pro30 Tem 2024

  • CVE-2024-38892
    26İzleyin

    An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

    OrtaCVSS 6,5İstismar yokEPSS %0

    wavlink · wn551k1 firmware24 Haz 2024

  • CVE-2024-2088
    26İzleyin

    NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure

    OrtaCVSS 6,5İstismar yokEPSS %0

    nextscripts · social networks auto poster22 May 2024

  • CVE-2026-33530
    26İzleyin

    InvenTree Vulnerable to ORM Filter Injection

    OrtaCVSS 6,5İstismar yokEPSS %0

    inventree project · inventree26 Mar 2026

  • CVE-2025-64528
    25İzleyin

    Users are able to find users by name even when `enable_names` is off

    OrtaCVSS 6,3İstismar yokEPSS %0

    discourse · discourse30 Ara 2025

  • CVE-2021-1372
    22İzleyin

    Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability

    OrtaCVSS 5,5İstismar yokEPSS %0

    cisco · webex meetings17 Şub 2021

  • CVE-2023-20215
    21İzleyin

    A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote atta

    OrtaCVSS 5,3İstismar yokEPSS %1

    cisco · asyncos3 Ağu 2023

  • CVE-2024-20388
    21İzleyin

    A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote at

    OrtaCVSS 5,3İstismar yokEPSS %0

    cisco · firepower management center23 Eki 2024

  • CVE-2024-38897
    21İzleyin

    WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

    OrtaCVSS 5,3İstismar yokEPSS %0

    wavlink · wn551k1 firmware24 Haz 2024

  • CVE-2026-3546
    21İzleyin

    e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJ

    OrtaCVSS 5,3İstismar yokEPSS %0

    forfront · e-shot21 Mar 2026

  • CVE-2024-38895
    21İzleyin

    WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

    OrtaCVSS 5,3İstismar yokEPSS %0

    wavlink · wn551k1 firmware24 Haz 2024

Tüm zafiyet sınıfları