CWE-402: CWE-402
Yearly Trend
Top Affected Vendors
All CWE-402 CVEs (16)
This vulnerability allows attackers to access private files and directories in CrafterCMS through improper resource handling. It affects all CrafterCM...
Jan 15, 2025This vulnerability in Vaadin Designer allows remote attackers to access project source files through specially crafted HTTP requests due to overly per...
Apr 23, 2021This vulnerability in Vaadin's OSGi integration allows attackers to access server-side application classes and resources via crafted HTTP requests. It...
Apr 23, 2021Django-Select2 versions before 8.4.1 leak secret access tokens across requests in HeavySelect2Mixin subclasses, allowing unauthorized users to access ...
May 27, 2025CVE-2021-23264 allows unauthenticated remote attackers to create, view, and delete search indexes in unprotected crafter-search installations. This af...
Dec 2, 2021Electron Packager versions before 18.3.1 leak random segments of Node.js heap memory into bundled executables, potentially exposing sensitive informat...
Mar 29, 2024CVE-2022-3596 is an information disclosure vulnerability in OpenStack's undercloud that allows unauthenticated remote attackers to access sensitive da...
Sep 20, 2023This vulnerability in XWiki Platform allows attackers to retrieve email addresses of all users even when mail obfuscation is enabled. While emails app...
Jun 23, 2023MyHoard versions 1.0.1 through 1.2.x log backup information including encryption keys in certain cases, potentially exposing sensitive database backup...
Dec 18, 2025This vulnerability allows an attacker to obtain the serial number of Ruijie Reyee OS devices by sniffing RAW WiFi signals when physically adjacent. It...
Dec 6, 2024This vulnerability in Plesk Obsidian allows unauthenticated attackers to access AWS credentials via a specific endpoint. It affects Plesk Obsidian 18....
Jul 3, 2025A firewall misconfiguration in Kerlink devices running KerOS prior to version 5.12 allows attackers to bypass firewall protections by sending speciall...
Dec 1, 2025XWiki Platform REST endpoints improperly list protected pages even when users lack view permissions. This information disclosure vulnerability affects...
Mar 19, 2025The YouDao plugin in StarDict sends X11 clipboard selections to remote servers via unencrypted HTTP, exposing potentially sensitive copied text to net...
Aug 4, 2025This vulnerability in Tryton's trytond server allows remote attackers to obtain sensitive trace-back information that reveals server setup details. It...
Nov 30, 2025This vulnerability in Zammad allows logged-in customers to view and manipulate shared article drafts intended only for agents. Customers can access co...
Apr 5, 2025About CWE-402 (CWE-402)
Our database tracks 16 CVEs classified as CWE-402, with 1 rated critical and 8 rated high severity. The average CVSS score for CWE-402 vulnerabilities is 6.8.
External reference: View CWE-402 on MITRE CWE →
Monitor CWE-402 Vulnerabilities
Get alerted when new CWE-402 CVEs affect your infrastructure.
Start Monitoring Free