CWE-202: CWE-202

10
Total CVEs
1
Critical
6
High
7.2
Avg CVSS

Yearly Trend

2026
2
2025
6
2024
1
2021
1

Top Affected Vendors

1 Dell 1
2 Craftcms 1
3 Debian 1
4 Phpmyfaq 1
5 Discourse 1
6 Langfuse 1
7 Icinga 1
8 Audiobookshelf 1
9 Restful Web Services Project 1
10 Finrota 1

All CWE-202 CVEs (10)

CVE-2025-68456
9.1

Unauthenticated attackers can trigger database backup operations in vulnerable Craft CMS versions, potentially causing resource exhaustion or exposing...

Jan 5, 2026
CVE-2021-32743
8.8

Icinga 2 monitoring system exposes sensitive credentials (database, Redis, Elasticsearch passwords) through its API to authenticated users with read p...

Jul 15, 2021
CVE-2025-25205
8.2

A vulnerability in Audiobookshelf versions 2.17.0 through 2.19.0 allows unauthenticated attackers to bypass authentication by crafting URLs with speci...

Feb 12, 2025
CVE-2025-69200
7.5

An unauthenticated remote attacker can trigger generation and download of configuration backup ZIP files in vulnerable phpMyFAQ installations. This ex...

Dec 29, 2025
CVE-2025-29981
7.5

Dell Wyse Management Suite versions before 5.1 expose sensitive information through data queries. Unauthenticated remote attackers can exploit this vu...

Apr 2, 2025
CVE-2024-13255
7.5

This vulnerability in Drupal's RESTful Web Services module allows attackers to access sensitive information through forceful browsing of data queries....

Jan 9, 2025
CVE-2024-6400
7.5

This vulnerability in Finrota Netahsilat allows attackers to retrieve sensitive information stored in cleartext, bypass authentication, inject IMAP/SM...

Oct 4, 2024
CVE-2026-25050
5.3

This vulnerability allows attackers to enumerate valid user accounts (email addresses) in Vendure through timing attacks. By measuring response time d...

Jan 30, 2026
CVE-2025-64528
5.3

This vulnerability in Discourse allows attackers to discover users' full names even when the 'enable_names' setting is disabled, by using partial user...

Dec 30, 2025
CVE-2025-64504
5.0

This vulnerability in Langfuse allows authenticated users to enumerate names and email addresses of users in other organizations if they know the targ...

Nov 10, 2025

About CWE-202 (CWE-202)

Our database tracks 10 CVEs classified as CWE-202, with 1 rated critical and 6 rated high severity. The average CVSS score for CWE-202 vulnerabilities is 7.2.

External reference: View CWE-202 on MITRE CWE →

Monitor CWE-202 Vulnerabilities

Get alerted when new CWE-202 CVEs affect your infrastructure.

Start Monitoring Free