Skip to main content

CWE archive

CWE-497 CVEs

Programmatic archive

351 CVEs tagged with CWE-49712 Critical, 60 High, 251 Medium, 28 Low, 0 Unrated.

CVE-2025-0055

Published Jan 14, 2025

SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2024-52367

Published Jan 7, 2025

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthorized actor that could be used in further attacks against the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12993

Published Dec 30, 2024

Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’…

CVSS 4.8 · Medium

CVE-2024-52321

Published Dec 23, 2024

Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be re…

CVSS 5.9 · Medium

CVE-2024-54279

Published Dec 16, 2024

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolkit wp-nerd-toolkit.This issue affects WP-NERD Toolkit: from…

CVSS 7.5 · High

CVE-2024-53867

Published Dec 3, 2024

Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in…

CVSS 4.3 · Medium

CVE-2024-25035

Published Dec 3, 2024

IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53768

Published Nov 30, 2024

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ideinteractive Content Audit Exporter content-audit-exporter allows Retrieve Embedded S…

CVSS 5.3 · Medium

CVE-2024-22037

Published Nov 28, 2024

The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still…

CVSS 5.7 · Medium

CVE-2024-10240

Published Nov 26, 2024

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 b…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9929

Published Nov 26, 2024

A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.

CVSS 4.3 · Medium

CVE-2024-52033

Published Nov 20, 2024

Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploite…

CVSS 5.3 · Medium

CVE-2024-37070

Published Nov 19, 2024

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52582

Published Nov 19, 2024

Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build process network-isolated. Prior to version 0.14.0, secrets m…

CVSS 4.7 · Medium

CVE-2021-1234

Published Nov 18, 2024

A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36509

Published Nov 12, 2024

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below,…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47799

Published Nov 12, 2024

Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is e…

CVSS 3.5 · Low

CVE-2024-50528

Published Nov 4, 2024

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50425

Published Oct 29, 2024

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Murg WP Booking System wp-booking-system.This issue affects WP Booking System: f…

CVSS 6.5 · Medium

CVE-2024-48024

Published Oct 17, 2024

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Daily keep-backup-daily allows Retrieve Embedded Sensitive Da…

CVSS 7.5 · High
Showing 276-300 of 351 CVEsPage 12 of 15