CWE-359: CWE-359

63
Total CVEs
1
Critical
25
High
6.1
Avg CVSS

Yearly Trend

2026
7
2025
41
2024
11
2023
3
2022
1

Top Affected Vendors

1 Apple 12
2 Microsoft 5
3 Fortinet 2
4 Wwbn 2
5 Gitlab 2
6 Nextcloud 1
7 Teamviewer 1
8 Transsion 1
9 Utarit 1
10 Dokploy 1

All CWE-359 CVEs (63)

CVE-2025-53374
4.3

An authenticated low-privileged user in Dokploy can access detailed profile information of other users in the same organization, exposing personally-i...

Jul 7, 2025
CVE-2025-0679
4.3

This vulnerability in GitLab CE/EE allows unauthorized users to view full email addresses that should be partially obscured under certain conditions. ...

May 22, 2025
CVE-2025-25042
4.3

An authenticated low-privilege attacker can exploit the AOS-CX REST interface vulnerability to view encrypted credentials of other users on affected s...

Mar 18, 2025
CVE-2024-13217
4.3

The Jeg Elementor Kit WordPress plugin exposes sensitive template data through insecure functions. Authenticated attackers with Contributor-level acce...

Feb 27, 2025
CVE-2024-13216
4.3

The HT Event WordPress plugin (versions up to 1.4.7) exposes sensitive template data through an information disclosure vulnerability. Authenticated at...

Jan 31, 2025
CVE-2024-6053
4.3

This vulnerability allows unintentional clipboard sharing during TeamViewer meetings. When a user joins a meeting, their clipboard content could be ex...

Aug 28, 2024
CVE-2025-52602
4.2

HCL BigFix Query WebUI has an information disclosure vulnerability where HTTP GET requests can expose group names and active user IDs. This affects or...

Nov 5, 2025
CVE-2023-44255
4.1

This vulnerability allows authenticated administrators with read permissions in Fortinet FortiManager, FortiAnalyzer, and FortiAnalyzer-BigData to acc...

Nov 12, 2024
CVE-2025-10859
4.0

This vulnerability in Firefox for iOS incorrectly shared cookie storage between private (Incognito) and normal browsing sessions, allowing data from p...

Sep 30, 2025
CVE-2025-3950
3.5

This vulnerability in GitLab allows authenticated users to bypass asset proxy protection by referencing specially crafted images, potentially leaking ...

Jan 9, 2026
CVE-2025-11598
N/A

The mObywatel iOS application fails to properly clear sensitive data from the App Switcher preview, allowing unauthorized users to view personal infor...

Feb 3, 2026
CVE-2025-14317
N/A

This vulnerability allows authenticated attackers in the Crazy Bubble Tea mobile app to access other users' personal information by enumerating loyalt...

Jan 14, 2026
CVE-2025-13008
N/A

An authenticated attacker using M-Files Web can capture session tokens of other active users, potentially allowing impersonation and unauthorized acce...

Dec 19, 2025

About CWE-359 (CWE-359)

Our database tracks 63 CVEs classified as CWE-359, with 1 rated critical and 25 rated high severity. The average CVSS score for CWE-359 vulnerabilities is 6.1.

External reference: View CWE-359 on MITRE CWE →

Monitor CWE-359 Vulnerabilities

Get alerted when new CWE-359 CVEs affect your infrastructure.

Start Monitoring Free