VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (203)

page 7 of 11
  • CVE-2023-45721MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2023-45720MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2025-3035MedApr 1, 2025
    risk 0.34cvss 5.3epss 0.00

    By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability was fixed in Firefox 137.

  • CVE-2024-49765MedDec 19, 2024
    risk 0.34cvss 5.3epss 0.00

    Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse.…

  • CVE-2024-8891MedSep 18, 2024
    risk 0.34cvss 5.3epss 0.00

    An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware version 1.0.4.

  • CVE-2022-2720MedOct 12, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.

  • CVE-2026-54264MedJun 22, 2026
    risk 0.33cvss 6.1epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular…

  • CVE-2026-25699MedJun 9, 2026
    risk 0.33cvss 6.1epss 0.00

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or…

  • CVE-2025-62644MedOct 17, 2025
    risk 0.33cvss 5.0epss 0.00

    The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.

  • CVE-2024-13953MedMay 22, 2025
    risk 0.32cvss 4.9epss 0.00

    Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2021-46687MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.01

    JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.31.10 versions prior to 7.x; JFrog Artifactory versions…

  • CVE-2025-68945MedDec 26, 2025
    risk 0.31cvss 5.8epss 0.00

    In Gitea before 1.21.2, an anonymous user can visit a private user's project.

  • CVE-2026-28963MedMay 11, 2026
    risk 0.30cvss 4.6epss 0.00

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensitive user data during iPhone Mirroring.

  • CVE-2026-20834MedJan 13, 2026
    risk 0.30cvss 4.6epss 0.01

    Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

  • CVE-2025-36131MedNov 7, 2025
    risk 0.30cvss 4.6epss 0.00

    IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party with physical access to the system.

  • CVE-2025-43452MedNov 4, 2025
    risk 0.30cvss 4.6epss 0.00

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggestions may display sensitive information on the lock screen.

  • CVE-2025-43259MedJul 30, 2025
    risk 0.30cvss 4.6epss 0.00

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2025-43310MedSep 15, 2025
    risk 0.29cvss 4.4epss 0.00

    A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to trick a user into copying sensitive data to the pasteboard.

  • CVE-2025-53765MedAug 12, 2025
    risk 0.29cvss 4.4epss 0.00

    Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.

  • CVE-2026-58510MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private