CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Description
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-170 · CAPEC-694
CVEs mapped to this weakness (378)
page 19 of 19| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-50294 | Med | 0.00 | 6.2 | 0.00 | Jul 14, 2026 | Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-61977 | Med | 0.00 | 5.3 | 0.00 | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2. | ||
| CVE-2026-61976 | Med | 0.00 | 5.3 | 0.00 | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0. | ||
| CVE-2026-61975 | Med | 0.00 | 5.3 | 0.00 | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1. | ||
| CVE-2026-57393 | Med | 0.00 | 6.5 | 0.00 | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8. | ||
| CVE-2026-14808 | Cri | 0.00 | 9.8 | 0.00 | Jul 6, 2026 | Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password. | ||
| CVE-2026-57753 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions. | ||
| CVE-2026-56124 | Hig | 0.00 | 7.5 | 0.00 | Jun 29, 2026 | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and… | ||
| CVE-2026-57664 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions. | ||
| CVE-2026-57633 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions. | ||
| CVE-2026-57316 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions. | ||
| CVE-2026-56060 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | ||
| CVE-2026-54824 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions. | ||
| CVE-2025-62524 | Med | 0.00 | 5.3 | 0.00 | Oct 27, 2025 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By header, enabling attackers to fingerprint the server and assess potential exploits. This information disclosure vulnerability… | ||
| CVE-2025-54422 | Med | 0.00 | 5.5 | 0.00 | Jul 29, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via… | ||
| CVE-2024-6388 | Med | 0.00 | 5.9 | 0.00 | Jun 27, 2024 | Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext. | ||
| CVE-2022-4968 | Med | 0.00 | 6.5 | 0.00 | Jun 7, 2024 | netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected. | ||
| CVE-2022-1902 | Hig | 0.00 | 8.8 | 0.01 | Sep 1, 2022 | A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges. |
- risk 0.00cvss 6.2epss 0.00
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.3epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.
- risk 0.00cvss 5.3epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.
- risk 0.00cvss 5.3epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
- risk 0.00cvss 6.5epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.
- risk 0.00cvss 9.8epss 0.00
Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
- risk 0.00cvss 7.5epss 0.00
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and…
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
- risk 0.00cvss 5.3epss 0.00
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By header, enabling attackers to fingerprint the server and assess potential exploits. This information disclosure vulnerability…
- risk 0.00cvss 5.5epss 0.00
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via…
- risk 0.00cvss 5.9epss 0.00
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
- risk 0.00cvss 6.5epss 0.00
netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
- risk 0.00cvss 8.8epss 0.01
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.