CWE-497— Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.— MITRE CWE catalog
414 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-497page 1 of 9
- CVE-2021-31955CRITICALCVSS 5.5EG 9.0⚠ KEV2021-06-08
Windows Kernel Information Disclosure Vulnerability
- CVE-2025-10264CRITICALCVSS 10.0EG 10.02025-09-12
Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remoter attackers to access the system configuration file and obtain plaintext credentials of the NVR and its conn…
- CVE-2026-27494CRITICALCVSS 9.9EG 9.92026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could use the Python Code node to escape the sandbox. The sandbox did no…
- CVE-2025-47699CRITICALCVSS 9.9EG 9.92025-10-23
Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices. …
- CVE-2025-44823CRITICALCVSS 8.8EG 9.92025-10-07
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.
- CVE-2026-14808CRITICALCVSS 9.8EG 9.82026-07-06
Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.
- CVE-2024-13999CRITICALCVSS 9.8EG 9.82025-10-30
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authe…
- CVE-2025-6561CRITICALCVSS 9.8EG 9.82025-06-26
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext…
- CVE-2025-5893CRITICALCVSS 9.8EG 9.82025-06-09
Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain plaintext administrator credentials.
- CVE-2025-1144CRITICALCVSS 9.8EG 9.82025-02-11
School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as plaintext administrator credentials.
- CVE-2024-36554CRITICALCVSS 9.8EG 9.82025-02-06
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allow a malicious user to gain information about the device by sending a…
- CVE-2020-25179CRITICALCVSS 9.8EG 9.82020-12-14
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
- CVE-2024-4008CRITICALCVSS 9.6EG 9.62024-06-05
FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System
- CVE-2025-11545CRITICALCVSS 9.5EG 9.52025-12-22
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attacker may improperly access the HTTP server and execute arbitrary actions.
- CVE-2023-32550CRITICALCVSS 9.3EG 9.32023-06-06
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
- CVE-2026-44945CRITICALCVSS 9.1EG 9.12026-08-05
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher contr…
- CVE-2025-12779HIGHCVSS 8.8EG 8.82025-11-05
Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8, may expose the authentication token for DCV-based WorkSpaces to other local users on the same client machine. Under ce…
- CVE-2024-13995HIGHCVSS 8.8EG 8.82025-10-30
Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Expo…
- CVE-2025-9364HIGHCVSS 8.8EG 8.82025-09-09
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
- CVE-2024-39675HIGHCVSS 8.8EG 8.82024-07-09
A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.10), RUGGEDCOM RP110 (All versions < V4.3.10), RUGGEDCOM RP110NC (All versions < V4.3.10), RUGGEDCOM RS400 (All version…
- CVE-2022-1902HIGHCVSS 8.8EG 8.82022-09-01
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secre…
- CVE-2026-0240HIGHCVSS 8.7EG 8.72026-05-13
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any …
- CVE-2025-59098HIGHCVSS 8.7EG 8.72026-01-26
The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality is implemented as a simple TCP socket. A tool called TraceClient.exe, provided by dormakaba via the Access Manager web…
- CVE-2022-4985HIGHCVSS 8.7EG 8.72025-11-14
Vodafone H500s devices running firmware v3.5.10 (hardware model Sercomm VFH500) expose the WiFi access point password via an unauthenticated HTTP endpoint. By sending a crafted GET request to /data/activation.json with specific headers and…
- CVE-2025-4364HIGHCVSS 8.7EG 8.72025-05-20
The affected products could allow an unauthenticated attacker to access system information that could enable further access to sensitive files and obtain administrative credentials.
- CVE-2025-32792HIGHCVSS 8.7EG 8.72025-04-18
SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior to version 1.12.0, web pages and web extensions using `ses` and the Compartment API to evaluate th…
- CVE-2024-8313HIGHCVSS 8.7EG 8.72025-03-25
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based …
- CVE-2025-0061HIGHCVSS 8.7EG 8.72025-01-14
SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modif…
- CVE-2026-28698HIGHCVSS 8.6EG 8.62026-07-23
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
- CVE-2026-42047HIGHCVSS 8.6EG 8.62026-05-07
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfilt…
- CVE-2026-24222HIGHCVSS 8.6EG 8.62026-04-28
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host …
- CVE-2026-34413HIGHCVSS 8.6EG 8.62026-04-22
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() …
- CVE-2024-12367HIGHCVSS 8.6EG 8.62025-09-16
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing. This issue affects Vega Master: from v.1.12.35 through 20250916. NOTE: The vendor did …
- CVE-2022-28651HIGHCVSS 8.4EG 8.42022-04-05
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
- CVE-2025-9986HIGHCVSS 8.2EG 8.22026-02-11
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information Systems Ltd. Co. DIGIKENT allows Excavation. This issue affects DIGIKENT: through 13092025.
- CVE-2025-11151HIGHCVSS 8.2EG 8.22025-10-21
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beyaz Bilgisayar Software Design Industry and Trade Ltd. Co. CityPLus allows Detect Unp…
- CVE-2026-38058HIGHCVSS 8.1EG 8.12026-09-11
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with vali…
- CVE-2025-13691HIGHCVSS 6.5EG 8.12026-02-17
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.
- CVE-2026-107914HIGHCVSS 7.8EG 7.82026-10-09
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested …
- CVE-2026-80119HIGHCVSS 7.8EG 7.82026-09-04
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dum…
- CVE-2023-4237HIGHCVSS 7.8EG 7.82023-10-04
A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromis…
- CVE-2024-45549HIGHCVSS 7.7EG 7.72025-04-07
Information disclosure while creating MQ channels.
- CVE-2025-22222HIGHCVSS 7.7EG 7.72025-01-30
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID i…
- CVE-2022-20664HIGHCVSS 7.7EG 7.72022-06-15
A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve s…
- CVE-2025-30686HIGHCVSS 7.6EG 7.62025-04-15
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: EMC). Supported versions that are affected are 19.1-19.7. Easily exploitable vulnerability allows low privileged attacker with n…
- CVE-2026-102387HIGHCVSS 7.5EG 7.52026-10-06
Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions.
- CVE-2026-71330HIGHCVSS 7.5EG 7.52026-09-08
Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to disclose information over a network.
- CVE-2026-66840HIGHCVSS 7.5EG 7.52026-09-04
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
- CVE-2026-81774HIGHCVSS 7.5EG 7.52026-09-02
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
- CVE-2026-78268HIGHCVSS 7.5EG 7.52026-08-24
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
Map vulnerabilities like CWE-497 to your infrastructure
EchelonGraph correlates every CVE — across CWE-497 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →