VYPR

CWE-202

Exposure of Sensitive Information Through Data Queries

BaseDraftLikelihood: Medium

Description

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

In situations where data should not be tied to individual users, but a large number of users should be able to make queries that "scrub" the identity of users, it may be possible to get information about a user -- e.g., by specifying search terms that are known to be unique to that user.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (40)

page 2 of 2
  • CVE-2019-19000MedApr 2, 2020
    risk 0.42cvss 6.5epss 0.01

    For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.

  • CVE-2023-1625HigSep 24, 2023
    risk 0.41cvss 7.4epss 0.01

    An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of…

  • CVE-2023-20215MedAug 3, 2023
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should have been blocked. This vulnerability is due to improper…

  • CVE-2021-1372MedFeb 17, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected…

  • CVE-2026-3546MedMar 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registered as a wp_ajax_ AJAX handler accessible to all authenticated users. The…

  • CVE-2024-20388MedOct 23, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote attacker to determine valid user names on an affected device. This vulnerability is due to improper authentication of password update…

  • CVE-2024-38897MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

  • CVE-2024-38895MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

  • CVE-2026-42797MedMay 25, 2026
    risk 0.32cvss 4.9epss 0.00

    Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access…

  • CVE-2021-34782MedOct 6, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the API endpoints for Cisco DNA Center could allow an authenticated, remote attacker to gain access to sensitive information that should be restricted. The attacker must have valid device credentials. This vulnerability is due to improper access controls on…

  • CVE-2019-19091MedApr 2, 2020
    risk 0.28cvss 4.3epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.

  • CVE-2026-25050MedJan 30, 2026
    risk 0.27cvss 5.3epss 0.00

    Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses). In `packages/core/src/config/auth/native-a…

  • CVE-2025-69226MedJan 5, 2026
    risk 0.27cvss 5.3epss 0.00

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path normalization logic for static files meant to prevent path traversal. If an…

  • CVE-2025-30086MedJul 25, 2025
    risk 0.25cvss 4.9epss 0.01

    CNCF Harbor 2.13.x before 2.13.1 and 2.12.x before 2.12.4 allows information disclosure by administrators who can exploit an ORM Leak present in the /api/v2.0/users endpoint to leak users' password hash and salt values. The q URL parameter allows a user to filter users by any…

  • CVE-2023-0785LowFeb 12, 2023
    risk 0.24cvss 3.7epss 0.01

    A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information…

  • CVE-2026-25703HigAug 5, 2026
    risk 0.00cvss 7.3epss 0.00

    NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

  • CVE-2025-64528MedDec 30, 2025
    risk 0.00cvss 5.3epss 0.00

    Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0…

  • CVE-2025-64504MedNov 10, 2025
    risk 0.00cvss 5.0epss 0.00

    Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership APIs, the server trusted a user‑controlled orgId and used it in authorization checks. As a result, any…

  • CVE-2025-25205HigFeb 12, 2025
    risk 0.00cvss 8.2epss 0.04

    Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs…

  • CVE-2021-4159MedAug 24, 2022
    risk 0.00cvss 4.4epss 0.00

    A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory…