CWE-359: CWE-359
Yearly Trend
Top Affected Vendors
All CWE-359 CVEs (63)
An authenticated low-privileged user in Dokploy can access detailed profile information of other users in the same organization, exposing personally-i...
Jul 7, 2025This vulnerability in GitLab CE/EE allows unauthorized users to view full email addresses that should be partially obscured under certain conditions. ...
May 22, 2025An authenticated low-privilege attacker can exploit the AOS-CX REST interface vulnerability to view encrypted credentials of other users on affected s...
Mar 18, 2025The Jeg Elementor Kit WordPress plugin exposes sensitive template data through insecure functions. Authenticated attackers with Contributor-level acce...
Feb 27, 2025The HT Event WordPress plugin (versions up to 1.4.7) exposes sensitive template data through an information disclosure vulnerability. Authenticated at...
Jan 31, 2025This vulnerability allows unintentional clipboard sharing during TeamViewer meetings. When a user joins a meeting, their clipboard content could be ex...
Aug 28, 2024HCL BigFix Query WebUI has an information disclosure vulnerability where HTTP GET requests can expose group names and active user IDs. This affects or...
Nov 5, 2025This vulnerability allows authenticated administrators with read permissions in Fortinet FortiManager, FortiAnalyzer, and FortiAnalyzer-BigData to acc...
Nov 12, 2024This vulnerability in Firefox for iOS incorrectly shared cookie storage between private (Incognito) and normal browsing sessions, allowing data from p...
Sep 30, 2025This vulnerability in GitLab allows authenticated users to bypass asset proxy protection by referencing specially crafted images, potentially leaking ...
Jan 9, 2026The mObywatel iOS application fails to properly clear sensitive data from the App Switcher preview, allowing unauthorized users to view personal infor...
Feb 3, 2026This vulnerability allows authenticated attackers in the Crazy Bubble Tea mobile app to access other users' personal information by enumerating loyalt...
Jan 14, 2026An authenticated attacker using M-Files Web can capture session tokens of other active users, potentially allowing impersonation and unauthorized acce...
Dec 19, 2025About CWE-359 (CWE-359)
Our database tracks 63 CVEs classified as CWE-359, with 1 rated critical and 25 rated high severity. The average CVSS score for CWE-359 vulnerabilities is 6.1.
External reference: View CWE-359 on MITRE CWE →
Monitor CWE-359 Vulnerabilities
Get alerted when new CWE-359 CVEs affect your infrastructure.
Start Monitoring Free