VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (217)

page 7 of 11
  • CVE-2019-15623MedFeb 4, 2020
    risk 0.35cvss 5.3epss 0.02

    Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled.

  • CVE-2017-16769MedFeb 23, 2018
    risk 0.35cvss 5.3epss 0.02

    Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.

  • CVE-2026-53497MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originating IP addresses, User-Agent strings,…

  • CVE-2020-25900MedJun 5, 2026
    risk 0.34cvss 5.3epss 0.00

    HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)

  • CVE-2026-8990MedMay 28, 2026
    risk 0.34cvss —epss 0.00

    A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue was fixed in version 4.4.3

  • CVE-2026-41182MedApr 23, 2026
    risk 0.34cvss 5.3epss 0.00

    LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to…

  • CVE-2026-6765MedApr 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

  • CVE-2026-24321MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on…

  • CVE-2025-66605MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields on this webpage with the autocomplete attribute enabled, the input content could be saved in the browser the user is using. The affected products and…

  • CVE-2025-31276MedJul 30, 2025
    risk 0.34cvss 5.3epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.

  • CVE-2023-45721MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2023-45720MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2025-3035MedApr 1, 2025
    risk 0.34cvss 5.3epss 0.00

    By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability was fixed in Firefox 137.

  • CVE-2024-49765MedDec 19, 2024
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse.…

  • CVE-2024-8891MedSep 18, 2024
    risk 0.34cvss 5.3epss 0.00

    An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.

  • CVE-2022-2720MedOct 12, 2022
    risk 0.34cvss 5.3epss 0.01

    In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.

  • CVE-2026-54264MedJun 22, 2026
    risk 0.33cvss 6.1epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular…

  • CVE-2026-25699MedJun 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or…

  • CVE-2025-62644MedOct 17, 2025
    risk 0.33cvss 5.0epss 0.00

    The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.

  • CVE-2024-13953MedMay 22, 2025
    risk 0.32cvss 4.9epss 0.00

    Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.