VYPR

CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

BaseIncomplete

Description

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-170 · CAPEC-694

CVEs mapped to this weakness (378)

page 18 of 19
  • CVE-2024-11035LowMar 5, 2025
    risk 0.16cvss 2.5epss 0.00

    Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information may b exposed due to a vulnerability in software.

  • CVE-2025-59447LowOct 6, 2025
    risk 0.14cvss 2.2epss 0.00

    The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can leverage this interface to read a boot log, which includes network access credentials.

  • CVE-2025-2236LowMay 27, 2025
    risk 0.14cvss epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the external services. This issue…

  • CVE-2025-46718LowMay 12, 2025
    risk 0.14cvss 3.3epss 0.00

    sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo…

  • CVE-2025-46717LowMay 12, 2025
    risk 0.14cvss 3.3epss 0.00

    sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges can determine whether files exists in folders that they otherwise cannot access using `sudo --list `. Users with local access…

  • CVE-2025-34442HigDec 17, 2025
    risk 0.03cvss 7.5epss 0.01

    AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying filesystem structure and facilitating more effective attack chains.

  • CVE-2026-58246MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow…

  • CVE-2026-66438MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

  • CVE-2026-65564MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

  • CVE-2026-59548HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.

  • CVE-2026-59528HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

  • CVE-2025-59178MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

  • CVE-2026-65535MedJul 23, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

  • CVE-2026-65521MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

  • CVE-2026-65505MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

  • CVE-2026-65490MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.

  • CVE-2026-65474MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

  • CVE-2026-61945MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

  • CVE-2023-37507HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

  • CVE-2026-10588MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.