Skip to main content

CWE archive

CWE-497 CVEs

Programmatic archive

351 CVEs tagged with CWE-49712 Critical, 60 High, 251 Medium, 28 Low, 0 Unrated.

CVE-2025-32251

Published Apr 4, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedback Exporter jetpack-feedback-exporter allows Retrieve Embe…

CVSS 5.3 · Medium

CVE-2025-0278

Published Apr 3, 2025

HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31832

Published Apr 1, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector acf-city-selector allows Retrieve Embedded Sensitive Data.This i…

CVSS 5.3 · Medium

CVE-2025-30802

Published Apr 1, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPBean Our Team Members our-team-members.This issue affects Our Team Members: from n/a…

CVSS 4.3 · Medium

CVE-2025-27149

Published Mar 31, 2025

Zulip server provides an open-source team chat that helps teams stay productive and focused. Prior to 10.0, the data export to organization administrators feature in Zulip leaks p…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8313

Published Mar 25, 2025

An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R…

CVSS 8.7 · High

CVE-2025-2598

Published Mar 21, 2025

When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS cred…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10940

Published Mar 20, 2025

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The…

CVSS 5.3 · Medium

CVE-2025-23382

Published Mar 19, 2025

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A h…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11035

Published Mar 5, 2025

Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information may b exposed due…

CVSS 2.5 · Low

CVE-2025-26911

Published Feb 25, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard system-dashboard allows Exploiting Incorrectly Configured Access…

CVSS 4.3 · Medium

CVE-2025-26758

Published Feb 17, 2025

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social Media Feeds spotlight-social-photo-feeds allows Retrieve Emb…

CVSS 5.3 · Medium

CVE-2025-1212

Published Feb 12, 2025

An information disclosure vulnerability in GitLab CE/EE affecting all versions from 8.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1144

Published Feb 11, 2025

School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as p…

CVSS 9.8 · Critical

CVE-2024-8550

Published Feb 10, 2025

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36554

Published Feb 6, 2025

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a mali…

CVSS 9.8 · Critical

CVE-2025-22222

Published Jan 30, 2025

VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials…

CVSS 7.7 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-53683

Published Jan 17, 2025

A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use…

CVSS 5.6 · Medium

CVE-2024-11029

Published Jan 15, 2025

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently…

CVSS 5.5 · Medium

CVE-2025-0061

Published Jan 14, 2025

SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an informa…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-0059

Published Jan 14, 2025

Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2025-0056

Published Jan 14, 2025

SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating Syste…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
28.9
Showing 251-275 of 351 CVEsPage 11 of 15