VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (203)

page 10 of 11
  • CVE-2022-24719LowMar 1, 2022
    risk 0.10cvss 2.6epss 0.01

    Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirectsWith` with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a request that includes confidential headers such as…

  • CVE-2025-11598LowFeb 3, 2026
    risk 0.07cvss epss 0.00

    In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the…

  • CVE-2025-5009LowOct 8, 2025
    risk 0.07cvss epss 0.00

    In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable public link that contained the entire conversation history and not just the snippet.

  • CVE-2025-34441HigDec 17, 2025
    risk 0.03cvss 7.5epss 0.01

    AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.

  • CVE-2026-56171HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.00

    Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-50657MedJul 14, 2026
    risk 0.00cvss 4.7epss 0.00

    Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.

  • CVE-2026-62328HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated request logs and retrieve complete AI…

  • CVE-2026-58297HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.00

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58296HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.00

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-57960MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET…

  • CVE-2026-56124HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.00

    phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and…

  • CVE-2025-66510MedDec 5, 2025
    risk 0.00cvss 4.5epss 0.00

    Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names,…

  • CVE-2025-66027MedNov 29, 2025
    risk 0.00cvss 6.5epss 0.00

    Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy…

  • CVE-2025-59843MedSep 26, 2025
    risk 0.00cvss 5.3epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email…

  • CVE-2025-53374MedJul 7, 2025
    risk 0.00cvss 4.3epss 0.00

    Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly…

  • CVE-2024-53258MedNov 25, 2024
    risk 0.00cvss 5.3epss 0.00

    Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for…

  • CVE-2023-25819MedMar 4, 2023
    risk 0.00cvss 5.3epss 0.01

    Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. This affects any site running the `tests-passed` or `beta` branches >= 3.1.0.beta2. The issue is patched in the latest `beta` and `tests-passed` version of…

  • CVE-2023-26041LowFeb 27, 2023
    risk 0.00cvss 2.6epss 0.01

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended that the Nextcloud Talk…

  • CVE-2022-46168LowJan 5, 2023
    risk 0.00cvss 3.5epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users inside the group SMTP topic.…

  • CVE-2022-41971MedDec 1, 2022
    risk 0.00cvss 4.8epss 0.01

    Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call…