VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (203)

page 2 of 11
  • CVE-2025-43496HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    The issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Remote content may be loaded even when the 'Load Remote Images' setting is…

  • CVE-2025-43405HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.01

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

  • CVE-2025-43399HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.01

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access protected user data.

  • CVE-2025-11145HigOct 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account…

  • CVE-2025-43227HigJul 30, 2025
    risk 0.49cvss 7.5epss 0.01

    This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose sensitive user information.

  • CVE-2025-49715HigJun 20, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-5334HigMay 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be…

  • CVE-2024-10267HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that is already in use. The server…

  • CVE-2024-11216HigMar 5, 2025
    risk 0.49cvss 7.6epss 0.00

    Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking. This issue affects Pik Online: before 3.1.5.

  • CVE-2025-20060HigFeb 28, 2025
    risk 0.49cvss 7.5epss 0.00

    An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.

  • CVE-2024-11206HigNov 14, 2024
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.

  • CVE-2024-7697HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.

  • CVE-2024-36682HigJun 24, 2024
    risk 0.49cvss 7.5epss 0.00

    In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is…

  • CVE-2024-36677HigJun 19, 2024
    risk 0.49cvss 7.5epss 0.00

    In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account of the Shop if the module is not installed OR if a secret accessible to administrator is stolen.

  • CVE-2023-50053HigApr 30, 2024
    risk 0.49cvss 7.6epss 0.01

    An issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Foundation, the signed message lacks a nonce (random number)

  • CVE-2024-33271HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component.

  • CVE-2024-28387HigMar 25, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.

  • CVE-2023-5983HigNov 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Botanik Software Pharmacy Automation allows Retrieve Embedded Sensitive Data. This issue affects Pharmacy Automation: before 2.1.133.0.

  • CVE-2023-44156HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-2703HigMay 23, 2023
    risk 0.49cvss 7.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Management System: before 23.07.