CWE-202 · 34 kayıt
Exposure of Sensitive Information Through Data Queries
Bu sınıftaki CVE’ler
34 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2021-32743İstismar yok | Passwords used to access external services inadvertently exposed through APIicinga · icinga · CWE-202 | Yüksek8,8 | — | %1,8 | 15 Tem 2021 |
33İzleyin | CVE-2025-25205Silahlaştırılmış | Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matchingaudiobookshelf · audiobookshelf · CWE-202 | Yüksek8,2 | — | %4,8 | 12 Şub 2025 |
32İzleyin | CVE-2024-6400İstismar yok | Cleartext Storage of Username and Password in Finrota's Netahsilatfinrota · finrota · CWE-202 | Yüksek8,2 | — | %0,6 | 4 Eki 2024 |
31İzleyin | CVE-2025-69200Kavram kanıtı | phpMyFAQ has unauthenticated config backup download via /api/setup/backupphpmyfaq · phpmyfaq · CWE-202 | Yüksek7,5 | — | %2,1 | 29 Ara 2025 |
30İzleyin | CVE-2022-41623İstismar yok | WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerabilityvillatheme · dropshipping and fulfillment for aliexpress and woocommerce · CWE-202 | Yüksek7,5 | — | %0,8 | 14 Eki 2022 |
30İzleyin | CVE-2023-7072İstismar yok | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpointpickplugins · post grid combo · CWE-202 | Yüksek7,5 | — | %0,6 | 12 Mar 2024 |
30İzleyin | CVE-2026-30778İstismar yok | Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.apache · skywalking · CWE-202 | Yüksek7,5 | — | %0,6 | 15 Nis 2026 |
30İzleyin | CVE-2024-13255İstismar yok | RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019restful web services project · restful web services · CWE-202 | Yüksek7,5 | — | %0,5 | 9 Oca 2025 |
30İzleyin | CVE-2025-29981İstismar yok | Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.dell · wyse management suite · CWE-202 | Yüksek7,5 | — | %0,4 | 1 Nis 2025 |
30İzleyin | CVE-2025-36575İstismar yok | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.dell · wyse management suite · CWE-202 | Yüksek7,5 | — | %0,3 | 10 Haz 2025 |
29İzleyin | CVE-2026-25703Kavram kanıtı | Potential information leakage from manager /network/graph API in NeuVectorsuse · neuvector · CWE-202 | Yüksek7,3 | — | %0,8 | 5 Ağu 2026 |
28İzleyin | CVE-2025-68456İstismar yok | Unauthenticated Craft CMS users can trigger a database backupcraftcms · craft cms · CWE-202 | Yüksek7,0 | — | %0,5 | 5 Oca 2026 |
26İzleyin | CVE-2022-20747İstismar yok | Cisco SD-WAN vManage Software Information Disclosure Vulnerabilitycisco · catalyst sd-wan manager · CWE-202 | Orta6,5 | — | %0,9 | 15 Nis 2022 |
26İzleyin | CVE-2022-20810İstismar yok | Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerabilitycisco · ios xe · CWE-202 | Orta6,5 | — | %0,8 | 30 Eyl 2022 |
26İzleyin | CVE-2024-1287İstismar yok | Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQListrangerstudios · paid memberships pro · CWE-202 | Orta6,5 | — | %0,5 | 30 Tem 2024 |
26İzleyin | CVE-2024-38892İstismar yok | An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.wavlink · wn551k1 firmware · CWE-202 | Orta6,5 | — | %0,4 | 24 Haz 2024 |
26İzleyin | CVE-2024-2088İstismar yok | NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposurenextscripts · social networks auto poster · CWE-202 | Orta6,5 | — | %0,3 | 22 May 2024 |
26İzleyin | CVE-2026-33530İstismar yok | InvenTree Vulnerable to ORM Filter Injectioninventree project · inventree · CWE-202 | Orta6,5 | — | %0,3 | 26 Mar 2026 |
25İzleyin | CVE-2025-64528İstismar yok | Users are able to find users by name even when `enable_names` is offdiscourse · discourse · CWE-202 | Orta6,3 | — | %0,3 | 30 Ara 2025 |
22İzleyin | CVE-2021-1372İstismar yok | Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerabilitycisco · webex meetings · CWE-202 | Orta5,5 | — | %0,4 | 17 Şub 2021 |
21İzleyin | CVE-2023-20215İstismar yok | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacisco · asyncos · CWE-202 | Orta5,3 | — | %0,6 | 3 Ağu 2023 |
21İzleyin | CVE-2024-20388İstismar yok | A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote atcisco · firepower management center · CWE-202 | Orta5,3 | — | %0,4 | 23 Eki 2024 |
21İzleyin | CVE-2024-38897İstismar yok | WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.wavlink · wn551k1 firmware · CWE-202 | Orta5,3 | — | %0,4 | 24 Haz 2024 |
21İzleyin | CVE-2026-3546İstismar yok | e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJforfront · e-shot · CWE-202 | Orta5,3 | — | %0,4 | 21 Mar 2026 |
21İzleyin | CVE-2024-38895İstismar yok | WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.wavlink · wn551k1 firmware · CWE-202 | Orta5,3 | — | %0,4 | 24 Haz 2024 |
- CVE-2021-3274336İzleyin
Passwords used to access external services inadvertently exposed through API
YüksekCVSS 8,8İstismar yokEPSS %2icinga · icinga15 Tem 2021
- CVE-2025-2520533İzleyin
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
YüksekCVSS 8,2SilahlaştırılmışEPSS %5audiobookshelf · audiobookshelf12 Şub 2025
- CVE-2024-640032İzleyin
Cleartext Storage of Username and Password in Finrota's Netahsilat
YüksekCVSS 8,2İstismar yokEPSS %1finrota · finrota4 Eki 2024
- CVE-2025-6920031İzleyin
phpMyFAQ has unauthenticated config backup download via /api/setup/backup
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpmyfaq · phpmyfaq29 Ara 2025
- CVE-2022-4162330İzleyin
WordPress ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 - Sensitive Data Exposure vulnerability
YüksekCVSS 7,5İstismar yokEPSS %1villatheme · dropshipping and fulfillment for aliexpress and woocommerce14 Eki 2022
- CVE-2023-707230İzleyin
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint
YüksekCVSS 7,5İstismar yokEPSS %1pickplugins · post grid combo12 Mar 2024
- CVE-2026-3077830İzleyin
Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
YüksekCVSS 7,5İstismar yokEPSS %1apache · skywalking15 Nis 2026
- CVE-2024-1325530İzleyin
RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019
YüksekCVSS 7,5İstismar yokEPSS %1restful web services project · restful web services9 Oca 2025
- CVE-2025-2998130İzleyin
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %0dell · wyse management suite1 Nis 2025
- CVE-2025-3657530İzleyin
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %0dell · wyse management suite10 Haz 2025
- CVE-2026-2570329İzleyin
Potential information leakage from manager /network/graph API in NeuVector
YüksekCVSS 7,3Kavram kanıtıEPSS %1suse · neuvector5 Ağu 2026
- CVE-2025-6845628İzleyin
Unauthenticated Craft CMS users can trigger a database backup
YüksekCVSS 7,0İstismar yokEPSS %1craftcms · craft cms5 Oca 2026
- CVE-2022-2074726İzleyin
Cisco SD-WAN vManage Software Information Disclosure Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %1cisco · catalyst sd-wan manager15 Nis 2022
- CVE-2022-2081026İzleyin
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Information Disclosure Vulnerability
OrtaCVSS 6,5İstismar yokEPSS %1cisco · ios xe30 Eyl 2022
- CVE-2024-128726İzleyin
Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi
OrtaCVSS 6,5İstismar yokEPSS %1strangerstudios · paid memberships pro30 Tem 2024
- CVE-2024-3889226İzleyin
An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.
OrtaCVSS 6,5İstismar yokEPSS %0wavlink · wn551k1 firmware24 Haz 2024
- CVE-2024-208826İzleyin
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure
OrtaCVSS 6,5İstismar yokEPSS %0nextscripts · social networks auto poster22 May 2024
- CVE-2026-3353026İzleyin
InvenTree Vulnerable to ORM Filter Injection
OrtaCVSS 6,5İstismar yokEPSS %0inventree project · inventree26 Mar 2026
- CVE-2025-6452825İzleyin
Users are able to find users by name even when `enable_names` is off
OrtaCVSS 6,3İstismar yokEPSS %0discourse · discourse30 Ara 2025
- CVE-2021-137222İzleyin
Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability
OrtaCVSS 5,5İstismar yokEPSS %0cisco · webex meetings17 Şub 2021
- CVE-2023-2021521İzleyin
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote atta
OrtaCVSS 5,3İstismar yokEPSS %1cisco · asyncos3 Ağu 2023
- CVE-2024-2038821İzleyin
A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote at
OrtaCVSS 5,3İstismar yokEPSS %0cisco · firepower management center23 Eki 2024
- CVE-2024-3889721İzleyin
WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
OrtaCVSS 5,3İstismar yokEPSS %0wavlink · wn551k1 firmware24 Haz 2024
- CVE-2026-354621İzleyin
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJ
OrtaCVSS 5,3İstismar yokEPSS %0forfront · e-shot21 Mar 2026
- CVE-2024-3889521İzleyin
WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.
OrtaCVSS 5,3İstismar yokEPSS %0wavlink · wn551k1 firmware24 Haz 2024