CWE-359 · 191 kayıt
Exposure of Private Personal Information to an Unauthorized Actor
Bu sınıftaki CVE’ler
191 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2022-0482Kavram kanıtı | Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-359 | Kritik9,1 | — | %43,7 | 9 Mar 2022 |
40Planlayın | CVE-2023-36052İstismar yok | Azure CLI REST Command Information Disclosure Vulnerabilitymicrosoft · azure command-line interface · CWE-359 | Yüksek8,6 | — | %21,1 | 14 Kas 2023 |
39İzleyin | CVE-2023-36018İstismar yok | Visual Studio Code Jupyter Extension Spoofing Vulnerabilitymicrosoft · jupyter · CWE-359 | Kritik9,8 | — | %1,5 | 14 Kas 2023 |
37İzleyin | CVE-2025-15623İstismar yok | Sparx Pro Cloud Server reveals sensitive information to an unauthenticated usersparxsystems · pro cloud server · CWE-359 | Kritik9,3 | — | %0,3 | 17 Nis 2026 |
36İzleyin | CVE-2024-49765İstismar yok | Bypass of Discourse Connect using other login paths if enabled in Discoursediscourse · discourse · CWE-359 | Kritik9,1 | — | %0,4 | 19 Ara 2024 |
35İzleyin | CVE-2022-2921İstismar yok | Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserpnotrinos · notrinoserp · CWE-359 | Yüksek8,8 | — | %1,3 | 21 Ağu 2022 |
34İzleyin | CVE-2025-54125Kavram kanıtı | XWiki Platform: Password and email exposure in xml.vm fieldsxwiki · xwiki · CWE-359 | Yüksek8,7 | — | %1,3 | 5 Ağu 2025 |
34İzleyin | CVE-2019-25762İstismar yok | Joomla! Component JoomProject 1.1.3.2 Information Disclosurejoomboost · joomproject · CWE-359 | Yüksek8,7 | — | %0,7 | 19 Haz 2026 |
34İzleyin | CVE-2026-56124İstismar yok | phpUploader < 2.0.2 Unauthenticated Database Exposure via index modelshimosyan · phpuploader · CWE-359 | Yüksek8,7 | — | %0,6 | 29 Haz 2026 |
34İzleyin | CVE-2026-62328İstismar yok | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpointsdecolua · 9router · CWE-359 | Yüksek8,7 | — | %0,6 | 13 Tem 2026 |
34İzleyin | CVE-2020-37173İstismar yok | AVideo Platform 8.1 - Information Disclosure (User Enumeration)wwbn · avideo · CWE-359 | Yüksek8,7 | — | %0,6 | 11 Şub 2026 |
34İzleyin | CVE-2025-13008İstismar yok | Session Token Disclosure in M-Files Webm-files corporation · m-files server · CWE-359 | Yüksek8,6 | — | %0,5 | 19 Ara 2025 |
34İzleyin | CVE-2025-53625İstismar yok | DynamicPageList3 exposes hidden/suppressed usernamesuniversal-omega · dynamicpagelist3 · CWE-359 | Yüksek8,7 | — | %0,4 | 10 Tem 2025 |
34İzleyin | CVE-2024-45787İstismar yok | Information Disclosure Vulnerabilityreedos · aim-star · CWE-359 | Yüksek8,7 | — | %0,4 | 11 Eyl 2024 |
34İzleyin | CVE-2024-47087İstismar yok | Information Disclosure Vulnerabilityapexsoftcell · ld geo · CWE-359 | Yüksek8,7 | — | %0,4 | 19 Eyl 2024 |
34İzleyin | CVE-2024-47085İstismar yok | Parameter Manipulation Vulnerabilityapexsoftcell · ld geo · CWE-359 | Yüksek8,7 | — | %0,4 | 19 Eyl 2024 |
34İzleyin | CVE-2025-20060İstismar yok | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actordario health · usb-c blood glucose monitoring system starter kit android applications · CWE-359 | Yüksek8,7 | — | %0,4 | 28 Şub 2025 |
33İzleyin | CVE-2026-57960İstismar yok | Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_idhieventsdev · hi.events · CWE-359 | Yüksek8,3 | — | %0,4 | 29 Haz 2026 |
33İzleyin | CVE-2025-10450İstismar yok | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.rti · connext professional · CWE-359 | Yüksek8,3 | — | %0,2 | 16 Ara 2025 |
32İzleyin | CVE-2024-26192İstismar yok | Microsoft Edge (Chromium-based) Information Disclosure Vulnerabilitymicrosoft · edge chromium · CWE-359 | Yüksek8,2 | — | %1,5 | 23 Şub 2024 |
32İzleyin | CVE-2025-0683İstismar yok | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitorcontec health · cms8000 patient monitor · CWE-359 | Yüksek8,2 | — | %0,8 | 30 Oca 2025 |
32İzleyin | CVE-2024-30321İstismar yok | A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versiosiemens · simatic pcs 7 v9.1 · CWE-359 | Yüksek8,2 | — | %0,5 | 9 Tem 2024 |
32İzleyin | CVE-2025-66172İstismar yok | Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access toapache · cloudstack · CWE-359 | Yüksek8,1 | — | %0,5 | 8 May 2026 |
32İzleyin | CVE-2025-11959İstismar yok | Improper Access Control in Premierturk's Excavation Management Information Systempremierturk information technologies inc. · excavation management information system · CWE-359 | Yüksek8,1 | — | %0,3 | 11 Kas 2025 |
30İzleyin | CVE-2021-3980İstismar yok | Exposure of Private Personal Information to an Unauthorized Actor in elgg/elggelgg · elgg · CWE-359 | Yüksek7,5 | — | %1,6 | 3 Ara 2021 |
- CVE-2022-048249Planlayın
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
KritikCVSS 9,1Kavram kanıtıEPSS %44easyappointments · easyappointments9 Mar 2022
- CVE-2023-3605240Planlayın
Azure CLI REST Command Information Disclosure Vulnerability
YüksekCVSS 8,6İstismar yokEPSS %21microsoft · azure command-line interface14 Kas 2023
- CVE-2023-3601839İzleyin
Visual Studio Code Jupyter Extension Spoofing Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2microsoft · jupyter14 Kas 2023
- CVE-2025-1562337İzleyin
Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user
KritikCVSS 9,3İstismar yokEPSS %0sparxsystems · pro cloud server17 Nis 2026
- CVE-2024-4976536İzleyin
Bypass of Discourse Connect using other login paths if enabled in Discourse
KritikCVSS 9,1İstismar yokEPSS %0discourse · discourse19 Ara 2024
- CVE-2022-292135İzleyin
Exposure of Private Personal Information to an Unauthorized Actor in notrinos/notrinoserp
YüksekCVSS 8,8İstismar yokEPSS %1notrinos · notrinoserp21 Ağu 2022
- CVE-2025-5412534İzleyin
XWiki Platform: Password and email exposure in xml.vm fields
YüksekCVSS 8,7Kavram kanıtıEPSS %1xwiki · xwiki5 Ağu 2025
- CVE-2019-2576234İzleyin
Joomla! Component JoomProject 1.1.3.2 Information Disclosure
YüksekCVSS 8,7İstismar yokEPSS %1joomboost · joomproject19 Haz 2026
- CVE-2026-5612434İzleyin
phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
YüksekCVSS 8,7İstismar yokEPSS %1shimosyan · phpuploader29 Haz 2026
- CVE-2026-6232834İzleyin
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
YüksekCVSS 8,7İstismar yokEPSS %1decolua · 9router13 Tem 2026
- CVE-2020-3717334İzleyin
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
YüksekCVSS 8,7İstismar yokEPSS %1wwbn · avideo11 Şub 2026
- CVE-2025-1300834İzleyin
Session Token Disclosure in M-Files Web
YüksekCVSS 8,6İstismar yokEPSS %0m-files corporation · m-files server19 Ara 2025
- CVE-2025-5362534İzleyin
DynamicPageList3 exposes hidden/suppressed usernames
YüksekCVSS 8,7İstismar yokEPSS %0universal-omega · dynamicpagelist310 Tem 2025
- CVE-2024-4578734İzleyin
Information Disclosure Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0reedos · aim-star11 Eyl 2024
- CVE-2024-4708734İzleyin
Information Disclosure Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0apexsoftcell · ld geo19 Eyl 2024
- CVE-2024-4708534İzleyin
Parameter Manipulation Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0apexsoftcell · ld geo19 Eyl 2024
- CVE-2025-2006034İzleyin
Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Private Personal Information to an Unauthorized Actor
YüksekCVSS 8,7İstismar yokEPSS %0dario health · usb-c blood glucose monitoring system starter kit android applications28 Şub 2025
- CVE-2026-5796033İzleyin
Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id
YüksekCVSS 8,3İstismar yokEPSS %0hieventsdev · hi.events29 Haz 2026
- CVE-2025-1045033İzleyin
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic.
YüksekCVSS 8,3İstismar yokEPSS %0rti · connext professional16 Ara 2025
- CVE-2024-2619232İzleyin
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
YüksekCVSS 8,2İstismar yokEPSS %2microsoft · edge chromium23 Şub 2024
- CVE-2025-068332İzleyin
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Contec Health CMS8000 Patient Monitor
YüksekCVSS 8,2İstismar yokEPSS %1contec health · cms8000 patient monitor30 Oca 2025
- CVE-2024-3032132İzleyin
A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versio
YüksekCVSS 8,2İstismar yokEPSS %1siemens · simatic pcs 7 v9.19 Tem 2024
- CVE-2025-6617232İzleyin
Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to
YüksekCVSS 8,1İstismar yokEPSS %1apache · cloudstack8 May 2026
- CVE-2025-1195932İzleyin
Improper Access Control in Premierturk's Excavation Management Information System
YüksekCVSS 8,1İstismar yokEPSS %0premierturk information technologies inc. · excavation management information system11 Kas 2025
- CVE-2021-398030İzleyin
Exposure of Private Personal Information to an Unauthorized Actor in elgg/elgg
YüksekCVSS 7,5İstismar yokEPSS %2elgg · elgg3 Ara 2021