İçeriğe atla
Noroxi

CWE-524 · 61 kayıt

Use of Cache Containing Sensitive Information

Bu sınıftaki CVE’ler

61 kayıt

  • CVE-2026-53943
    38İzleyin

    Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

    KritikCVSS 9,6İstismar yokEPSS %0

    tryghost · ghost24 Haz 2026

  • CVE-2026-19202
    36İzleyin

    Token Cache Reuse in mcp-toolbox-sdk-python

    KritikCVSS 9,1İstismar yokEPSS %0

    google · mcp-toolbox-sdk-python22 Eyl 2026

  • CVE-2026-93748
    34İzleyin

    http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale

    YüksekCVSS 8,7İstismar yokEPSS %1

    kornelski · http-cache-semantics18 Eyl 2026

  • CVE-2026-61836
    34İzleyin

    Directus: Authorization-dependent response served from unsegmented cache key

    YüksekCVSS 8,6İstismar yokEPSS %0

    monospace · directus15 Tem 2026

  • CVE-2026-50170
    32İzleyin

    Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache

    YüksekCVSS 8,2İstismar yokEPSS %0

    angular · angular22 Haz 2026

  • CVE-2025-64762
    32İzleyin

    authkit-nextjs may let session cookies be cached in CDNs

    YüksekCVSS 8,0İstismar yokEPSS %0

    workos · authkit-nextjs20 Kas 2025

  • CVE-2021-24027
    31İzleyin

    A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third p

    YüksekCVSS 7,5Kavram kanıtıEPSS %4

    whatsapp · whatsapp6 Nis 2021

  • CVE-2024-27917
    30İzleyin

    Shopware's session is persistent in Cache for 404 pages

    YüksekCVSS 7,5İstismar yokEPSS %1

    shopware · shopware6 Mar 2024

  • CVE-2023-37486
    30İzleyin

    Information Disclosure vulnerability in SAP Commerce (OCC API)

    YüksekCVSS 7,5İstismar yokEPSS %1

    sap · commerce cloud7 Ağu 2023

  • CVE-2026-71316
    30İzleyin

    Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

    YüksekCVSS 7,5İstismar yokEPSS %1

    nuxt · nuxt5 Ağu 2026

  • CVE-2023-45696
    30İzleyin

    HCL Sametime is impacted by an autocomplete enabled vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    hcltech · sametime9 Şub 2024

  • CVE-2026-64792
    30İzleyin

    Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions

    YüksekCVSS 7,5İstismar yokEPSS %0

    regularlabs.com · articles anywhere extension for joomla22 Tem 2026

  • CVE-2026-48901
    30İzleyin

    Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects

    YüksekCVSS 7,5İstismar yokEPSS %0

    joomla · joomla\!26 May 2026

  • CVE-2026-65755
    30İzleyin

    Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension

    YüksekCVSS 7,5İstismar yokEPSS %0

    regularlabs.com · articles anywhere extension for joomla23 Tem 2026

  • CVE-2026-59903
    30İzleyin

    Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite

    YüksekCVSS 7,5Kavram kanıtıEPSS %0

    netty · netty17 Ağu 2026

  • CVE-2023-37517
    30İzleyin

    HCL Domino Volt and Domino Leap are affected by missing "no cache" headers

    YüksekCVSS 7,5İstismar yokEPSS %0

    hcltech · domino leap30 Nis 2025

  • CVE-2024-12314
    28İzleyin

    Rapid Cache <= 1.2.3 - Unauthenticated Cache Poisoning

    YüksekCVSS 7,2İstismar yokEPSS %0

    megaoptim · rapid cache18 Şub 2025

  • CVE-2024-45596
    26İzleyin

    Directus's session is cached for OpenID and OAuth2 if `redirect` is not used

    OrtaCVSS 6,5İstismar yokEPSS %1

    monospace · directus10 Eyl 2024

  • CVE-2026-25540
    26İzleyin

    Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent keys (Web Cache Poisoning via `Rails.cache`)

    OrtaCVSS 6,5İstismar yokEPSS %0

    joinmastodon · mastodon4 Şub 2026

  • CVE-2026-82755
    25İzleyin

    ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion

    OrtaCVSS 6,3İstismar yokEPSS %1

    ash-project · ash_authentication_oauth2_server7 Eyl 2026

  • CVE-2026-89186
    25İzleyin

    mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches

    OrtaCVSS 6,3İstismar yokEPSS %1

    zenhive · mpp16 Eyl 2026

  • CVE-2025-61598
    25İzleyin

    Discourse is missing Cache-Control response header on error responses

    OrtaCVSS 6,3İstismar yokEPSS %0

    discourse · discourse28 Eki 2025

  • CVE-2024-41906
    25İzleyin

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0).

    OrtaCVSS 6,3İstismar yokEPSS %0

    siemens · sinec traffic analyzer13 Ağu 2024

  • CVE-2026-47225
    24İzleyin

    Improper Search Cache Isolation for Scoped Search API Keys in Typesense

    OrtaCVSS 6,0İstismar yokEPSS %0

    typesense · typesense12 Haz 2026

  • CVE-2025-57752
    24İzleyin

    Next.js Affected by Cache Key Confusion for Image Optimization API Routes

    OrtaCVSS 6,2İstismar yokEPSS %0

    vercel · next.js29 Ağu 2025

Tüm zafiyet sınıfları