CWE-359: CWE-359

63
Total CVEs
1
Critical
25
High
6.1
Avg CVSS

Yearly Trend

2026
7
2025
41
2024
11
2023
3
2022
1

Top Affected Vendors

1 Apple 12
2 Microsoft 5
3 Fortinet 2
4 Wwbn 2
5 Gitlab 2
6 Nextcloud 1
7 Teamviewer 1
8 Transsion 1
9 Utarit 1
10 Dokploy 1

All CWE-359 CVEs (63)

CVE-2022-0482
9.1

This vulnerability in Easy Appointments allows unauthorized actors to access private personal information stored in the application. It affects all us...

Mar 9, 2022
CVE-2023-36052
8.6

CVE-2023-36052 is an information disclosure vulnerability in Azure CLI's REST command that allows authenticated users to access sensitive information ...

Nov 14, 2023
CVE-2024-26192
8.2

This vulnerability in Microsoft Edge (Chromium-based) allows an attacker to potentially access sensitive information from the browser's memory. It aff...

Feb 23, 2024
CVE-2025-11959
8.1

This vulnerability in Premierturk's Excavation Management Information System allows unauthorized external parties to access files or directories, pote...

Nov 11, 2025
CVE-2024-42347
7.7

A malicious Matrix homeserver can manipulate user account data to force the matrix-react-sdk client to enable URL previews in end-to-end encrypted roo...

Aug 6, 2024
CVE-2024-11216
7.6

This vulnerability in PozitifIK Pik Online allows attackers to bypass authorization controls and access private personal information by manipulating u...

Mar 5, 2025
CVE-2020-37173
7.5

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.jso...

Feb 11, 2026
CVE-2026-24735
7.5

An unauthenticated API endpoint in Apache Answer exposes full revision history for deleted content, allowing unauthorized users to retrieve sensitive ...

Feb 4, 2026
CVE-2025-65857
7.5

This vulnerability in Xiongmai XM530 IP cameras exposes RTSP video streams through hardcoded credentials in the GetStreamUri function. Attackers can d...

Dec 22, 2025
CVE-2025-1030
7.5

This vulnerability in Utarit Informatics Services Inc. SoliClub allows unauthorized actors to query the system and access private personal information...

Dec 18, 2025
CVE-2025-34441
EPSS 42.3% 7.5

AVideo versions before 20.1 expose sensitive user information through an unauthenticated public API endpoint. This allows attackers to enumerate users...

Dec 17, 2025
CVE-2025-10450
7.5

CVE-2025-10450 is an exposure of private personal information vulnerability in RTI Connext Professional Core Libraries that allows unauthorized actors...

Dec 16, 2025
CVE-2025-43500
7.5

This CVE describes a privacy vulnerability in Apple operating systems where applications could bypass user preference controls to access sensitive use...

Nov 4, 2025
CVE-2025-43496
7.5

This vulnerability allows remote content to be loaded even when the 'Load Remote Images' setting is disabled in affected Apple operating systems. This...

Nov 4, 2025
CVE-2025-43405
7.5

A sandbox escape vulnerability in macOS allows malicious applications to bypass intended restrictions and access sensitive user data. This affects mac...

Nov 4, 2025
CVE-2025-43399
7.5

This vulnerability allows malicious apps to bypass privacy protections and access sensitive user data that should be restricted. It affects iOS, iPadO...

Nov 4, 2025
CVE-2025-43227
7.5

This vulnerability in Apple's WebKit browser engine allows malicious web content to bypass security controls and access sensitive user information. It...

Jul 30, 2025
CVE-2025-49715
7.5

This vulnerability in Dynamics 365 FastTrack Implementation Assets allows unauthorized attackers to access private personal information over the netwo...

Jun 20, 2025
CVE-2025-5334
7.5

This vulnerability in Devolutions Remote Desktop Manager allows authenticated users to access private personal information when entries are unintentio...

May 29, 2025
CVE-2025-20060
7.5

This vulnerability in the Dario Health Android application allows attackers to access cross-user personal identifiable information (PII) and personal ...

Feb 28, 2025
CVE-2024-7697
7.5

A logical vulnerability in the CarlCare mobile application (com.transsion.carlcare) exposes user information to unauthorized access. This affects user...

Aug 12, 2024
CVE-2024-36682
7.5

This vulnerability in the pk_themesettings module for PrestaShop allows unauthenticated guests to download a text file containing email addresses coll...

Jun 24, 2024
CVE-2023-44156
7.5

CVE-2023-44156 is a sensitive information disclosure vulnerability in Acronis Cyber Protect 15 caused by spell-jacking, which allows attackers to acce...

Sep 27, 2023
CVE-2023-2703
7.5

This CVE describes an exposure of private personal information vulnerability in Finex Media Competition Management System. It allows unauthorized acto...

May 23, 2023
CVE-2025-24355
7.1

Updatecli versions before 0.93.0 leak private Maven repository credentials in application logs when Maven source operations fail. This exposes authent...

Jan 24, 2025
CVE-2024-30056
7.1

This vulnerability in Microsoft Edge (Chromium-based) allows an attacker to potentially access sensitive information from the browser's memory. It aff...

May 25, 2024
CVE-2025-0969
6.5

The Brizy Page Builder WordPress plugin exposes administrator email addresses and password hashes to authenticated users with Contributor-level access...

Dec 13, 2025
CVE-2025-43279
6.2

This macOS vulnerability allows applications to access sensitive user data that should be redacted in system logs. It affects macOS systems before ver...

Sep 15, 2025
CVE-2025-0683
5.9

The Contec Health CMS8000 Patient Monitor transmits unencrypted patient data to a hard-coded public IP address when monitoring begins, potentially exp...

Jan 30, 2025
CVE-2025-68945
5.8

This vulnerability allows anonymous users to access private projects belonging to other users in Gitea instances. It affects all Gitea installations r...

Dec 26, 2025
CVE-2025-43409
5.5

A sandbox escape vulnerability in macOS allows malicious applications to bypass intended restrictions and access sensitive user data. This affects mac...

Nov 4, 2025
CVE-2025-43389
5.5

This CVE describes a privacy vulnerability in Apple operating systems where an application could access sensitive user data without proper authorizati...

Nov 4, 2025
CVE-2025-53950
5.5

This vulnerability allows authenticated administrators of Fortinet FortiDLP Agent's Outlookproxy plugin to collect email information from the current ...

Oct 16, 2025
CVE-2026-24321
5.3

SAP Commerce Cloud exposes sensitive API endpoints to unauthenticated users, allowing unauthorized access to confidential information. This affects or...

Feb 10, 2026
CVE-2025-66605
5.3

A vulnerability in Yokogawa's FAST/TOOLS software allows browser autocomplete to save sensitive input data from web interfaces. This affects industria...

Feb 9, 2026
CVE-2025-12536
5.3

The SureForms WordPress plugin exposes sensitive email notification configuration data to unauthenticated users due to improper access control. This v...

Nov 13, 2025
CVE-2025-59843
5.3

Flag Forge CTF platform versions 2.0.0 through 2.3.1 expose user email addresses through a public API endpoint. This vulnerability allows unauthentica...

Sep 26, 2025
CVE-2025-31276
5.3

This vulnerability allows remote content to be loaded in Apple's Mail app even when the 'Load Remote Images' privacy setting is disabled. It affects i...

Jul 30, 2025
CVE-2024-12041
5.3

This vulnerability allows unauthenticated attackers to access sensitive user information through the Directorist WordPress plugin's REST API endpoint....

Feb 1, 2025
CVE-2024-11396
EPSS 47.5% 5.3

The Event Monster WordPress plugin creates publicly accessible CSV files containing visitor personal data in the wp-content folder. Unauthenticated at...

Jan 14, 2025
CVE-2024-49765
5.3

Discourse sites using Discourse Connect (SSO) with local logins still enabled are vulnerable to authentication bypass. Attackers can create accounts a...

Dec 19, 2024
CVE-2024-8891
5.3

This vulnerability allows attackers to enumerate valid user accounts in CIRCUTOR Q-SMT devices by analyzing server responses to authentication attempt...

Sep 18, 2024
CVE-2024-40796
5.3

This CVE describes a privacy vulnerability in Apple operating systems where private browsing history may leak into system logs. The issue affects user...

Jul 29, 2024
CVE-2024-27881
5.3

This vulnerability allows applications to access sensitive contact information from macOS system logs due to insufficient data redaction. It affects m...

Jul 29, 2024
CVE-2025-62644
5.0

The RBI assistant platform's Global Store Directory improperly shares personal information among authenticated users, allowing one authenticated user ...

Oct 17, 2025
CVE-2024-13953
4.9

This vulnerability exposes sensitive device logger information in ABB ASPECT systems when administrator credentials are compromised. It affects ASPECT...

May 22, 2025
CVE-2025-36131
4.6

IBM Db2's clpplus command exposes user credentials in terminal output, allowing anyone with physical access to the system to view them. This affects D...

Nov 7, 2025
CVE-2025-66510
4.5

This vulnerability in Nextcloud Server allows authenticated users to retrieve personal data (emails, names, identifiers) of other users through the co...

Dec 5, 2025
CVE-2025-43310
4.4

This CVE describes a macOS vulnerability where malicious applications can trick users into copying sensitive data to the system clipboard. The issue a...

Sep 15, 2025
CVE-2025-53765
4.4

This vulnerability in Azure Stack allows an authorized attacker with local access to expose private personal information. It affects organizations usi...

Aug 12, 2025

About CWE-359 (CWE-359)

Our database tracks 63 CVEs classified as CWE-359, with 1 rated critical and 25 rated high severity. The average CVSS score for CWE-359 vulnerabilities is 6.1.

External reference: View CWE-359 on MITRE CWE →

Monitor CWE-359 Vulnerabilities

Get alerted when new CWE-359 CVEs affect your infrastructure.

Start Monitoring Free