CWE-359— Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.— MITRE CWE catalog
218 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-359page 1 of 5
- CVE-2022-0482CRITICALCVSS 9.1EG 9.12022-03-09
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
- CVE-2023-50719CRITICALCVSS 7.5EG 9.02023-12-15
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respec…
- CVE-2026-74969HIGHCVSS 8.8EG 8.82026-08-18
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- CVE-2022-2921HIGHCVSS 8.8EG 8.82022-08-21
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected fun…
- CVE-2025-53625HIGHCVSS 8.7EG 8.72025-07-10
The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revision deletion, suppre…
- CVE-2025-13008HIGHCVSS 8.6EG 8.62025-12-19
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
- CVE-2023-36052HIGHCVSS 8.6EG 8.62023-11-14
Azure CLI REST Command Information Disclosure Vulnerability
- CVE-2024-26192HIGHCVSS 8.2EG 8.22024-02-23
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2022-1252HIGHCVSS 8.2EG 8.22022-04-11
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. …
- CVE-2025-66172HIGHCVSS 8.1EG 8.12026-05-08
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is enabled and have access to specific APIs …
- CVE-2025-11959HIGHCVSS 8.1EG 8.12025-11-11
Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk Information Technologies Inc. Excavation Management Information System allows Footprinting,…
- CVE-2023-36018HIGHCVSS 7.8EG 7.82023-11-14
Visual Studio Code Jupyter Extension Spoofing Vulnerability
- CVE-2025-66035HIGHCVSS 7.7EG 7.72025-11-26
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in…
- CVE-2025-62644HIGHCVSS 7.7EG 7.72025-10-17
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.
- CVE-2024-42347HIGHCVSS 7.7EG 7.72024-08-06
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in whic…
- CVE-2024-11216HIGHCVSS 7.6EG 7.62025-03-05
Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking. This issue affects Pik Online: befor…
- CVE-2023-50053HIGHCVSS 7.6EG 7.62024-04-30
An issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication process of Foundation, the signed message lacks a nonce (random number)
- CVE-2023-2703HIGHCVSS 7.5EG 7.62023-05-23
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Finex Media Competition Management System allows Retrieve Embedded Sensitive Data, Collect Data as Provided by Users. This issue affects Competition Manage…
- CVE-2026-86904HIGHCVSS 7.5EG 7.52026-09-14
A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission.
- CVE-2026-84606HIGHCVSS 7.5EG 7.52026-09-14
A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to identify a user across reinstalls.
- CVE-2026-28938HIGHCVSS 7.5EG 7.52026-09-14
A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint the user.
- CVE-2026-74966HIGHCVSS 7.5EG 7.52026-08-18
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- CVE-2026-56171HIGHCVSS 7.5EG 7.52026-07-17
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-62328HIGHCVSS 7.5EG 7.52026-07-13
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated r…
- CVE-2026-56124HIGHCVSS 7.5EG 7.52026-06-29
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index mode…
- CVE-2026-48615HIGHCVSS 7.5EG 7.52026-06-26
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by lo…
- CVE-2019-25762HIGHCVSS 7.5EG 7.52026-06-19
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with o…
- CVE-2026-26237HIGHCVSS 7.5EG 7.52026-06-10
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the…
- CVE-2026-48048HIGHCVSS 7.5EG 7.52026-05-26
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified paramet…
- CVE-2026-28906HIGHCVSS 7.5EG 7.52026-05-11
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, visionOS 26.5. An attacker may be able …
- CVE-2025-15623HIGHCVSS 7.5EG 7.52026-04-17
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. Unauthenticated user can retri…
- CVE-2026-34226HIGHCVSS 7.5EG 7.52026-03-27
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(...,…
- CVE-2020-37173HIGHCVSS 7.5EG 7.52026-02-11
AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, passwo…
- CVE-2026-24735HIGHCVSS 7.5EG 7.52026-02-04
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted cont…
- CVE-2025-65857HIGHCVSS 7.5EG 7.52025-12-22
An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.
- CVE-2025-1030HIGHCVSS 7.5EG 7.52025-12-18
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Utarit Informatics Services Inc. SoliClub allows Query System for Information. This issue affects SoliClub: from 5.2.4 before 5.3.7.
- CVE-2025-10450HIGHCVSS 7.5EG 7.52025-12-16
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Libraries) allows Sniffing Network Traffic. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.2.0 befo…
- CVE-2025-43500HIGHCVSS 7.5EG 7.52025-11-04
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to access sensitive user data.
- CVE-2025-43496HIGHCVSS 7.5EG 7.52025-11-04
The issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Remote content may be loaded even when …
- CVE-2025-43405HIGHCVSS 7.5EG 7.52025-11-04
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.
- CVE-2025-43399HIGHCVSS 7.5EG 7.52025-11-04
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access protected user data.
- CVE-2025-11145HIGHCVSS 7.5EG 7.52025-10-24
Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trad…
- CVE-2025-43227HIGHCVSS 7.5EG 7.52025-07-30
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may disclose se…
- CVE-2025-49715HIGHCVSS 7.5EG 7.52025-06-20
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.
- CVE-2025-5334HIGHCVSS 7.5EG 7.52025-05-29
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specif…
- CVE-2024-10267HIGHCVSS 7.5EG 7.52025-03-20
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an e…
- CVE-2025-20060HIGHCVSS 7.5EG 7.52025-02-28
An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.
- CVE-2024-11206HIGHCVSS 7.5EG 7.52024-11-14
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.
- CVE-2024-7697HIGHCVSS 7.5EG 7.52024-08-12
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
- CVE-2024-36682HIGHCVSS 7.5EG 7.52024-06-24
In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file w…
Map vulnerabilities like CWE-359 to your infrastructure
EchelonGraph correlates every CVE — across CWE-359 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →