VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (203)

page 4 of 11
  • CVE-2024-47087MedSep 19, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to…

  • CVE-2024-47085MedSep 19, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request…

  • CVE-2024-45787MedSep 11, 2024
    risk 0.42cvss 6.5epss 0.00

    This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL and intercepting…

  • CVE-2024-27850MedJun 10, 2024
    risk 0.42cvss 6.5epss 0.01

    This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.

  • CVE-2024-29987MedApr 18, 2024
    risk 0.42cvss 6.5epss 0.01

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • CVE-2023-6695MedApr 9, 2024
    risk 0.42cvss 6.5epss 0.01

    The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including…

  • CVE-2023-35151HigJun 23, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki…

  • CVE-2023-22918MedApr 24, 2023
    risk 0.42cvss 6.5epss 0.01

    A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16…

  • CVE-2022-20942MedNov 4, 2022
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve…

  • CVE-2021-3980HigDec 3, 2021
    risk 0.42cvss 7.5epss 0.02

    elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

  • CVE-2020-1688MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.00

    On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and the authenticator services. Exploitation of this…

  • CVE-2016-11066HigJun 19, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.

  • CVE-2026-28950MedApr 22, 2026
    risk 0.41cvss 6.2epss 0.03

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications marked for deletion could be unexpectedly…

  • CVE-2025-43279MedSep 15, 2025
    risk 0.40cvss 6.2epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.

  • CVE-2025-20615MedFeb 13, 2025
    risk 0.40cvss 6.2epss 0.00

    The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the…

  • CVE-2021-36723MedDec 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.

  • CVE-2025-27080MedMar 18, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to…

  • CVE-2025-24355HigJan 24, 2025
    risk 0.39cvss 7.1epss 0.00

    Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source…

  • CVE-2025-0683MedJan 30, 2025
    risk 0.38cvss 5.9epss 0.01

    In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or…

  • CVE-2024-38103MedJul 25, 2024
    risk 0.38cvss 5.9epss 0.00

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability