Skip to main content

CWE archive

CWE-497 CVEs

Programmatic archive

351 CVEs tagged with CWE-49712 Critical, 60 High, 251 Medium, 28 Low, 0 Unrated.

CVE-2025-32299

Published May 16, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themovation QuickCal - Appointment Booking Calendar for WordPress quickcal allows Retri…

CVSS 4.3 · Medium

CVE-2025-31062

Published May 16, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist allows Retrieve Embedded Sensitive Data.This issue affects W…

CVSS 4.3 · Medium

CVE-2025-48024

Published May 15, 2025

In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1/settings endpoint.

CVSS 5.0 · Medium

CVE-2025-30011

Published May 13, 2025

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated att…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46747

Published May 12, 2025

An authenticated user without user-management permissions could identify other user accounts.

CVSS 5.7 · Medium

CVE-2025-46718

Published May 12, 2025

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list su…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-46717

Published May 12, 2025

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges can determine whether files exists…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-3506

Published May 8, 2025

Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that cou…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47540

Published May 7, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail wemail allows Retrieve Embedded Sensitive Data.This issue affects weMail:…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3606

Published Apr 25, 2025

Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing sensitive information, such as credentials which could be u…

CVSS 8.7 · High

CVE-2025-46421

Published Apr 24, 2025

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. Th…

CVSS 6.8 · Medium

CVE-2025-32792

Published Apr 18, 2025

SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior to version 1.12.0, web pages and web e…

CVSS 8.7 · High

CVE-2025-39439

Published Apr 17, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Markus Drubba wpLike2Get wplike2get allows Retrieve Embedded Sensitive Data.This issue…

CVSS 5.3 · Medium

CVE-2025-39589

Published Apr 16, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows R…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-39556

Published Apr 16, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sens…

CVSS 5.3 · Medium

CVE-2025-26730

Published Apr 15, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator with Admin Email Optin & Data. This issue affects Macro Calcu…

CVSS 7.5 · High

CVE-2025-30686

Published Apr 15, 2025

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: EMC). Supported versions that are affected are 19.1-19.7. Easily exp…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32228

Published Apr 10, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows…

CVSS 4.3 · Medium

CVE-2025-31003

Published Apr 9, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze squeeze allows Retrieve Embedded Sensitive Data.This issue af…

CVSS 2.7 · Low

CVE-2025-27934

Published Apr 9, 2025

Information disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote unauthenticated att…

CVSS 7.5 · High

CVE-2025-32164

Published Apr 8, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows Retrieve Embedded Sensitive Data.Th…

CVSS 6.5 · Medium

CVE-2025-32026

Published Apr 8, 2025

Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from…

CVSS 3.8 · Low

CVE-2025-32255

Published Apr 4, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList stafflist allows Retrieve Embedded Sensitive Data.This issue affects S…

CVSS 5.3 · Medium
Showing 226-250 of 351 CVEsPage 10 of 15