CWE-524 · 61 kayıt
Use of Cache Containing Sensitive Information
Bu sınıftaki CVE’ler
61 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2026-53943İstismar yok | Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview headertryghost · ghost · CWE-524 | Kritik9,6 | — | %0,4 | 24 Haz 2026 |
36İzleyin | CVE-2026-19202İstismar yok | Token Cache Reuse in mcp-toolbox-sdk-pythongoogle · mcp-toolbox-sdk-python · CWE-524 | Kritik9,1 | — | %0,3 | 22 Eyl 2026 |
34İzleyin | CVE-2026-93748İstismar yok | http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stalekornelski · http-cache-semantics · CWE-524 | Yüksek8,7 | — | %0,5 | 18 Eyl 2026 |
34İzleyin | CVE-2026-61836İstismar yok | Directus: Authorization-dependent response served from unsegmented cache keymonospace · directus · CWE-524 | Yüksek8,6 | — | %0,5 | 15 Tem 2026 |
32İzleyin | CVE-2026-50170İstismar yok | Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCacheangular · angular · CWE-524 | Yüksek8,2 | — | %0,4 | 22 Haz 2026 |
32İzleyin | CVE-2025-64762İstismar yok | authkit-nextjs may let session cookies be cached in CDNsworkos · authkit-nextjs · CWE-524 | Yüksek8,0 | — | %0,4 | 20 Kas 2025 |
31İzleyin | CVE-2021-24027Kavram kanıtı | A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third pwhatsapp · whatsapp · CWE-524 | Yüksek7,5 | — | %3,8 | 6 Nis 2021 |
30İzleyin | CVE-2024-27917İstismar yok | Shopware's session is persistent in Cache for 404 pagesshopware · shopware · CWE-524 | Yüksek7,5 | — | %0,6 | 6 Mar 2024 |
30İzleyin | CVE-2023-37486İstismar yok | Information Disclosure vulnerability in SAP Commerce (OCC API)sap · commerce cloud · CWE-524 | Yüksek7,5 | — | %0,5 | 7 Ağu 2023 |
30İzleyin | CVE-2026-71316İstismar yok | Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clientsnuxt · nuxt · CWE-524 | Yüksek7,5 | — | %0,5 | 5 Ağu 2026 |
30İzleyin | CVE-2023-45696İstismar yok | HCL Sametime is impacted by an autocomplete enabled vulnerabilityhcltech · sametime · CWE-524 | Yüksek7,5 | — | %0,4 | 9 Şub 2024 |
30İzleyin | CVE-2026-64792İstismar yok | Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensionsregularlabs.com · articles anywhere extension for joomla · CWE-524 | Yüksek7,5 | — | %0,4 | 22 Tem 2026 |
30İzleyin | CVE-2026-48901İstismar yok | Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objectsjoomla · joomla\! · CWE-524 | Yüksek7,5 | — | %0,4 | 26 May 2026 |
30İzleyin | CVE-2026-65755İstismar yok | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensionregularlabs.com · articles anywhere extension for joomla · CWE-524 | Yüksek7,5 | — | %0,4 | 23 Tem 2026 |
30İzleyin | CVE-2026-59903Kavram kanıtı | Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwritenetty · netty · CWE-524 | Yüksek7,5 | — | %0,2 | 17 Ağu 2026 |
30İzleyin | CVE-2023-37517İstismar yok | HCL Domino Volt and Domino Leap are affected by missing "no cache" headershcltech · domino leap · CWE-524 | Yüksek7,5 | — | %0,2 | 30 Nis 2025 |
28İzleyin | CVE-2024-12314İstismar yok | Rapid Cache <= 1.2.3 - Unauthenticated Cache Poisoningmegaoptim · rapid cache · CWE-524 | Yüksek7,2 | — | %0,4 | 18 Şub 2025 |
26İzleyin | CVE-2024-45596İstismar yok | Directus's session is cached for OpenID and OAuth2 if `redirect` is not usedmonospace · directus · CWE-524 | Orta6,5 | — | %0,7 | 10 Eyl 2024 |
26İzleyin | CVE-2026-25540İstismar yok | Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)joinmastodon · mastodon · CWE-524 | Orta6,5 | — | %0,4 | 4 Şub 2026 |
25İzleyin | CVE-2026-82755İstismar yok | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusionash-project · ash_authentication_oauth2_server · CWE-524 | Orta6,3 | — | %0,7 | 7 Eyl 2026 |
25İzleyin | CVE-2026-89186İstismar yok | mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared cacheszenhive · mpp · CWE-524 | Orta6,3 | — | %0,5 | 16 Eyl 2026 |
25İzleyin | CVE-2025-61598İstismar yok | Discourse is missing Cache-Control response header on error responsesdiscourse · discourse · CWE-524 | Orta6,3 | — | %0,3 | 28 Eki 2025 |
25İzleyin | CVE-2024-41906İstismar yok | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0).siemens · sinec traffic analyzer · CWE-524 | Orta6,3 | — | %0,2 | 13 Ağu 2024 |
24İzleyin | CVE-2026-47225İstismar yok | Improper Search Cache Isolation for Scoped Search API Keys in Typesensetypesense · typesense · CWE-524 | Orta6,0 | — | %0,4 | 12 Haz 2026 |
24İzleyin | CVE-2025-57752İstismar yok | Next.js Affected by Cache Key Confusion for Image Optimization API Routesvercel · next.js · CWE-524 | Orta6,2 | — | %0,3 | 29 Ağu 2025 |
- CVE-2026-5394338İzleyin
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
KritikCVSS 9,6İstismar yokEPSS %0tryghost · ghost24 Haz 2026
- CVE-2026-1920236İzleyin
Token Cache Reuse in mcp-toolbox-sdk-python
KritikCVSS 9,1İstismar yokEPSS %0google · mcp-toolbox-sdk-python22 Eyl 2026
- CVE-2026-9374834İzleyin
http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale
YüksekCVSS 8,7İstismar yokEPSS %1kornelski · http-cache-semantics18 Eyl 2026
- CVE-2026-6183634İzleyin
Directus: Authorization-dependent response served from unsegmented cache key
YüksekCVSS 8,6İstismar yokEPSS %0monospace · directus15 Tem 2026
- CVE-2026-5017032İzleyin
Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
YüksekCVSS 8,2İstismar yokEPSS %0angular · angular22 Haz 2026
- CVE-2025-6476232İzleyin
authkit-nextjs may let session cookies be cached in CDNs
YüksekCVSS 8,0İstismar yokEPSS %0workos · authkit-nextjs20 Kas 2025
- CVE-2021-2402731İzleyin
A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third p
YüksekCVSS 7,5Kavram kanıtıEPSS %4whatsapp · whatsapp6 Nis 2021
- CVE-2024-2791730İzleyin
Shopware's session is persistent in Cache for 404 pages
YüksekCVSS 7,5İstismar yokEPSS %1shopware · shopware6 Mar 2024
- CVE-2023-3748630İzleyin
Information Disclosure vulnerability in SAP Commerce (OCC API)
YüksekCVSS 7,5İstismar yokEPSS %1sap · commerce cloud7 Ağu 2023
- CVE-2026-7131630İzleyin
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
YüksekCVSS 7,5İstismar yokEPSS %1nuxt · nuxt5 Ağu 2026
- CVE-2023-4569630İzleyin
HCL Sametime is impacted by an autocomplete enabled vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0hcltech · sametime9 Şub 2024
- CVE-2026-6479230İzleyin
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions
YüksekCVSS 7,5İstismar yokEPSS %0regularlabs.com · articles anywhere extension for joomla22 Tem 2026
- CVE-2026-4890130İzleyin
Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects
YüksekCVSS 7,5İstismar yokEPSS %0joomla · joomla\!26 May 2026
- CVE-2026-6575530İzleyin
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension
YüksekCVSS 7,5İstismar yokEPSS %0regularlabs.com · articles anywhere extension for joomla23 Tem 2026
- CVE-2026-5990330İzleyin
Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
YüksekCVSS 7,5Kavram kanıtıEPSS %0netty · netty17 Ağu 2026
- CVE-2023-3751730İzleyin
HCL Domino Volt and Domino Leap are affected by missing "no cache" headers
YüksekCVSS 7,5İstismar yokEPSS %0hcltech · domino leap30 Nis 2025
- CVE-2024-1231428İzleyin
Rapid Cache <= 1.2.3 - Unauthenticated Cache Poisoning
YüksekCVSS 7,2İstismar yokEPSS %0megaoptim · rapid cache18 Şub 2025
- CVE-2024-4559626İzleyin
Directus's session is cached for OpenID and OAuth2 if `redirect` is not used
OrtaCVSS 6,5İstismar yokEPSS %1monospace · directus10 Eyl 2024
- CVE-2026-2554026İzleyin
Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)
OrtaCVSS 6,5İstismar yokEPSS %0joinmastodon · mastodon4 Şub 2026
- CVE-2026-8275525İzleyin
ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion
OrtaCVSS 6,3İstismar yokEPSS %1ash-project · ash_authentication_oauth2_server7 Eyl 2026
- CVE-2026-8918625İzleyin
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches
OrtaCVSS 6,3İstismar yokEPSS %1zenhive · mpp16 Eyl 2026
- CVE-2025-6159825İzleyin
Discourse is missing Cache-Control response header on error responses
OrtaCVSS 6,3İstismar yokEPSS %0discourse · discourse28 Eki 2025
- CVE-2024-4190625İzleyin
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0).
OrtaCVSS 6,3İstismar yokEPSS %0siemens · sinec traffic analyzer13 Ağu 2024
- CVE-2026-4722524İzleyin
Improper Search Cache Isolation for Scoped Search API Keys in Typesense
OrtaCVSS 6,0İstismar yokEPSS %0typesense · typesense12 Haz 2026
- CVE-2025-5775224İzleyin
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
OrtaCVSS 6,2İstismar yokEPSS %0vercel · next.js29 Ağu 2025