CWE-402: CWE-402

16
Total CVEs
1
Critical
8
High
6.8
Avg CVSS

Yearly Trend

2025
9
2024
2
2023
2
2021
3

Top Affected Vendors

1 Xwiki 2
2 Craftercms 2
3 Vaadin 2
4 Openjsf 1
5 Redhat 1
6 Kerlink 1
7 Ruijienetworks 1
8 Tryton 1
9 Aiven 1
10 Zammad 1

All CWE-402 CVEs (16)

CVE-2025-0502
9.1

This vulnerability allows attackers to access private files and directories in CrafterCMS through improper resource handling. It affects all CrafterCM...

Jan 15, 2025
CVE-2021-31410
8.6

This vulnerability in Vaadin Designer allows remote attackers to access project source files through specially crafted HTTP requests due to overly per...

Apr 23, 2021
CVE-2021-31407
8.6

This vulnerability in Vaadin's OSGi integration allows attackers to access server-side application classes and resources via crafted HTTP requests. It...

Apr 23, 2021
CVE-2025-48383
8.2

Django-Select2 versions before 8.4.1 leak secret access tokens across requests in HeavySelect2Mixin subclasses, allowing unauthorized users to access ...

May 27, 2025
CVE-2021-23264
8.1

CVE-2021-23264 allows unauthenticated remote attackers to create, view, and delete search indexes in unprotected crafter-search installations. This af...

Dec 2, 2021
CVE-2024-29900
7.5

Electron Packager versions before 18.3.1 leak random segments of Node.js heap memory into bundled executables, potentially exposing sensitive informat...

Mar 29, 2024
CVE-2022-3596
7.5

CVE-2022-3596 is an information disclosure vulnerability in OpenStack's undercloud that allows unauthenticated remote attackers to access sensitive da...

Sep 20, 2023
CVE-2023-34467
7.5

This vulnerability in XWiki Platform allows attackers to retrieve email addresses of all users even when mail obfuscation is enabled. While emails app...

Jun 23, 2023
CVE-2025-67745
7.1

MyHoard versions 1.0.1 through 1.2.x log backup information including encryption keys in certain cases, potentially exposing sensitive database backup...

Dec 18, 2025
CVE-2024-47146
6.5

This vulnerability allows an attacker to obtain the serial number of Ruijie Reyee OS devices by sniffing RAW WiFi signals when physically adjacent. It...

Dec 6, 2024
CVE-2025-49618
5.8

This vulnerability in Plesk Obsidian allows unauthenticated attackers to access AWS credentials via a specific endpoint. It affects Plesk Obsidian 18....

Jul 3, 2025
CVE-2024-32388
5.3

A firewall misconfiguration in Kerlink devices running KerOS prior to version 5.12 allows attackers to bypass firewall protections by sending speciall...

Dec 1, 2025
CVE-2025-29925
5.3

XWiki Platform REST endpoints improperly list protected pages even when users lack view permissions. This information disclosure vulnerability affects...

Mar 19, 2025
CVE-2025-55014
4.7

The YouDao plugin in StarDict sends X11 clipboard selections to remote servers via unencrypted HTTP, exposing potentially sensitive copied text to net...

Aug 4, 2025
CVE-2025-66422
4.3

This vulnerability in Tryton's trytond server allows remote attackers to obtain sensitive trace-back information that reveals server setup details. It...

Nov 30, 2025
CVE-2025-32360
4.2

This vulnerability in Zammad allows logged-in customers to view and manipulate shared article drafts intended only for agents. Customers can access co...

Apr 5, 2025

About CWE-402 (CWE-402)

Our database tracks 16 CVEs classified as CWE-402, with 1 rated critical and 8 rated high severity. The average CVSS score for CWE-402 vulnerabilities is 6.8.

External reference: View CWE-402 on MITRE CWE →

Monitor CWE-402 Vulnerabilities

Get alerted when new CWE-402 CVEs affect your infrastructure.

Start Monitoring Free