CWE-359— Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.— MITRE CWE catalog
218 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-359page 3 of 5
- CVE-2026-28950MEDIUMCVSS 6.2EG 6.22026-04-22
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2, iPadOS 17.7.11. Notifications mark…
- CVE-2025-43279MEDIUMCVSS 6.2EG 6.22025-09-15
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.
- CVE-2025-20615MEDIUMCVSS 6.2EG 6.22025-02-13
The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The…
- CVE-2026-28836MEDIUMCVSS 6.1EG 6.12026-09-14
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be able to silently persist an Apple Account on an erased device.
- CVE-2026-54264MEDIUMCVSS 6.1EG 6.12026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/servi…
- CVE-2026-25699MEDIUMCVSS 6.1EG 6.12026-06-09
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated u…
- CVE-2025-53950MEDIUMCVSS 6.0EG 6.02025-10-16
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through …
- CVE-2025-27080MEDIUMCVSS 6.0EG 6.02025-03-18
Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the im…
- CVE-2025-0683MEDIUMCVSS 5.9EG 5.92025-01-30
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient dat…
- CVE-2024-38103MEDIUMCVSS 5.9EG 5.92024-07-25
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-30321MEDIUMCVSS 5.9EG 5.92024-07-09
A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC W…
- CVE-2025-68945MEDIUMCVSS 5.8EG 5.82025-12-26
In Gitea before 1.21.2, an anonymous user can visit a private user's project.
- CVE-2024-49386MEDIUMCVSS 5.7EG 5.72024-10-17
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
- CVE-2026-73008MEDIUMCVSS 5.5EG 5.52026-09-08
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
- CVE-2026-69351MEDIUMCVSS 5.5EG 5.52026-09-08
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
- CVE-2026-50657MEDIUMCVSS 5.5EG 5.52026-07-14
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
- CVE-2025-30459MEDIUMCVSS 5.5EG 5.52026-06-11
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.
- CVE-2025-35981MEDIUMCVSS 5.5EG 5.52025-10-23
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view. This…
- CVE-2025-6017MEDIUMCVSS 5.5EG 5.52025-07-02
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials thr…
- CVE-2023-48680MEDIUMCVSS 5.5EG 5.52024-02-27
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.
- CVE-2023-25632MEDIUMCVSS 5.5EG 5.52023-11-27
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.
- CVE-2023-44213MEDIUMCVSS 5.5EG 5.52023-10-05
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 35739, Acronis Cyber Protect 16 (Windows) before build 37391.
- CVE-2022-0852MEDIUMCVSS 5.5EG 5.52022-08-29
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line v…
- CVE-2024-49025MEDIUMCVSS 5.4EG 5.42024-11-14
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-29986MEDIUMCVSS 5.4EG 5.42024-04-18
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
- CVE-2026-92565MEDIUMCVSS 5.3EG 5.32026-09-16
Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from publi…
- CVE-2026-53497MEDIUMCVSS 5.3EG 5.32026-08-21
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originati…
- CVE-2020-25900MEDIUMCVSS 5.3EG 5.32026-06-05
HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was cha…
- CVE-2026-8990MEDIUMCVSS 5.3EG 5.32026-05-28
A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue wa…
- CVE-2026-41182MEDIUMCVSS 5.3EG 5.32026-04-23
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_out…
- CVE-2026-6765MEDIUMCVSS 5.3EG 5.32026-04-21
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-24321MEDIUMCVSS 5.3EG 5.32026-02-10
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This v…
- CVE-2025-66605MEDIUMCVSS 5.3EG 5.32026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields on this webpage with the autocomplete attribute enabled, the input content could be saved in the browser the user is us…
- CVE-2025-12536MEDIUMCVSS 5.3EG 5.32025-11-13
The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration. This is due to setting the 'auth_callback' parameter…
- CVE-2025-59843MEDIUMCVSS 5.3EG 5.32025-09-26
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available sta…
- CVE-2025-31276MEDIUMCVSS 5.3EG 5.32025-07-30
This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.
- CVE-2025-49134MEDIUMCVSS 5.3EG 5.32025-06-16
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue ha…
- CVE-2023-45721MEDIUMCVSS 5.3EG 5.32025-04-30
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
- CVE-2023-45720MEDIUMCVSS 5.3EG 5.32025-04-24
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
- CVE-2025-3035MEDIUMCVSS 5.3EG 5.32025-04-01
By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability was fixed in Firefox 137.
- CVE-2024-12041MEDIUMCVSS 5.3EG 5.32025-02-01
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ end…
- CVE-2024-11396MEDIUMCVSS 5.3EG 5.32025-01-14
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file…
- CVE-2024-49765MEDIUMCVSS 5.3EG 5.32024-12-19
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patch…
- CVE-2024-11712MEDIUMCVSS 5.3EG 5.32024-12-14
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all ver…
- CVE-2024-53258MEDIUMCVSS 5.3EG 5.32024-11-25
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all…
- CVE-2024-46979MEDIUMCVSS 5.3EG 5.32024-09-18
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Co…
- CVE-2024-8891MEDIUMCVSS 5.3EG 5.32024-09-18
An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses as it indicates whether or not the user is present in CIRCUTOR Q-SMT in its firmware vers…
- CVE-2024-45591MEDIUMCVSS 5.3EG 5.32024-09-10
XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the ver…
- CVE-2024-40796MEDIUMCVSS 5.3EG 5.32024-07-29
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Private browsing may leak some browsin…
- CVE-2024-27881MEDIUMCVSS 5.3EG 5.32024-07-29
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.
Map vulnerabilities like CWE-359 to your infrastructure
EchelonGraph correlates every CVE — across CWE-359 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →