CWE-497: CWE-497

147
Total CVEs
6
Critical
35
High
5.9
Avg CVSS

Yearly Trend

2026
28
2025
100
2024
16
2023
2
2022
1

Top Affected Vendors

1 Ibm 14
2 Sap 4
3 Hcltech 3
4 Qualcomm 3
5 Apple 2
6 Canonical 2
7 Nagios 2
8 Sick 2
9 Zitadel 1
10 Themehunk 1

All CWE-497 CVEs (147)

CVE-2025-47699
9.9

This vulnerability in Gallagher Command Centre Server allows authenticated operators with limited site permissions to make unauthorized critical chang...

Oct 23, 2025
CVE-2025-44823
9.9

Nagios Log Server before version 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a specific API endpoint. This...

Oct 7, 2025
CVE-2025-1144
9.8

The School Affairs System from Quanxun exposes sensitive information to unauthenticated attackers, allowing them to access database information and pl...

Feb 11, 2025
CVE-2024-36554
9.8

This vulnerability in Forever KidsWatch smartwatches allows attackers to remotely extract sensitive device information by sending specially crafted SM...

Feb 6, 2025
CVE-2024-4008
9.6

This vulnerability allows attackers to gain unauthorized access to the local KNX bus system in ABB, Busch-Jaeger, and FTS building automation devices....

Jun 5, 2024
CVE-2023-32550
9.3

CVE-2023-32550 exposes sensitive system information through Landscape's server-status page, including GET requests that could enable attackers to gath...

Jun 6, 2023
CVE-2025-9364
8.8

An over-permissive Redis instance in affected Rockwell Automation products allows intranet attackers to access and potentially modify sensitive data. ...

Sep 9, 2025
CVE-2024-39675
8.8

This vulnerability in Siemens RUGGEDCOM industrial networking devices incorrectly enables the Modbus service in non-managed VLANs, potentially exposin...

Jul 9, 2024
CVE-2025-0061
8.7

SAP BusinessObjects Business Intelligence Platform has an information disclosure vulnerability that allows unauthenticated attackers to hijack user se...

Jan 14, 2025
CVE-2024-12367
8.6

This vulnerability allows unauthorized directory indexing in Vegagrup Software Vega Master, potentially exposing sensitive system information to attac...

Sep 16, 2025
CVE-2025-9986
8.2

This vulnerability in Vadi Corporate Information Systems' DIGIKENT software exposes sensitive system information to unauthorized parties. It affects a...

Feb 11, 2026
CVE-2025-13691
8.1

IBM DataStage on Cloud Pak for Data versions 5.1.2 through 5.3.0 returns sensitive information in HTTP responses that could enable user impersonation....

Feb 17, 2026
CVE-2024-45549
7.7

This vulnerability allows unauthorized information disclosure when creating MQ channels in affected Qualcomm products. Attackers can potentially acces...

Apr 7, 2025
CVE-2025-22222
7.7

VMware Aria Operations contains an information disclosure vulnerability where authenticated non-administrative users can retrieve credentials for outb...

Jan 30, 2025
CVE-2022-20664
7.7

This vulnerability allows authenticated attackers with operator-level credentials to retrieve sensitive information from LDAP authentication servers c...

Jun 15, 2022
CVE-2025-30686
7.6

This vulnerability in Oracle Hospitality Simphony allows authenticated attackers with low privileges to access sensitive data, modify information, and...

Apr 15, 2025
CVE-2026-24536
7.5

The Webpushr WordPress plugin (versions up to and including 4.38.0) contains a vulnerability that allows unauthorized users to retrieve sensitive syst...

Jan 23, 2026
CVE-2026-24523
7.5

This vulnerability in the WP FullCalendar WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects all...

Jan 23, 2026
CVE-2026-24377
7.5

This vulnerability in the Nexter Blocks WordPress plugin allows unauthorized users to retrieve embedded sensitive data from affected websites. It affe...

Jan 22, 2026
CVE-2025-9110
7.5

This CVE-2025-9110 vulnerability allows remote attackers to read sensitive system information from affected QNAP devices without authorization. Attack...

Jan 2, 2026
CVE-2025-68988
7.5

The E-Invoice App Malaysia WordPress plugin exposes sensitive system information to unauthorized users. This vulnerability allows attackers to retriev...

Dec 30, 2025
CVE-2025-68606
7.5

This vulnerability in the PostX WordPress plugin allows unauthorized users to retrieve embedded sensitive data from affected websites. It affects all ...

Dec 24, 2025
CVE-2025-68576
7.5

The Virusdie WordPress plugin versions up to and including 1.1.6 expose sensitive system information to unauthorized users. This vulnerability allows ...

Dec 24, 2025
CVE-2025-68494
7.5

This vulnerability in Premium Addons for Elementor WordPress plugin allows unauthorized users to retrieve embedded sensitive data from affected websit...

Dec 24, 2025
CVE-2025-67621
7.5

This vulnerability in the Eight Day Week Print Workflow WordPress plugin allows unauthorized users to retrieve embedded sensitive data. It affects all...

Dec 24, 2025
CVE-2025-64258
7.5

The Follow My Blog Post WordPress plugin (versions up to 2.3.9) exposes sensitive system information to unauthorized users. This vulnerability allows ...

Dec 18, 2025
CVE-2025-34442
EPSS 42.3% 7.5

AVideo versions before 20.1 expose absolute server filesystem paths through public API endpoints. This information disclosure vulnerability reveals in...

Dec 17, 2025
CVE-2025-14712
7.5

The Student Learning Assessment and Support System developed by JHENG GAO contains an information exposure vulnerability that allows unauthenticated r...

Dec 15, 2025
CVE-2025-43024
7.5

This vulnerability allows unauthorized users to view files in the file system through a GUI dialog in affected applications. It affects systems runnin...

Oct 28, 2025
CVE-2025-62902
7.5

This vulnerability in the WP Popup Builder WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects ...

Oct 27, 2025
CVE-2025-27721
7.5

Unauthorized users can bypass authentication in INFINITT PACS System Manager, allowing access to system resources without proper credentials. This aff...

Aug 21, 2025
CVE-2025-31045
7.5

The elfsight Contact Form widget for WordPress exposes sensitive system information to unauthorized users, allowing attackers to retrieve embedded sen...

Jun 9, 2025
CVE-2025-3606
7.5

Vestel AC Charger version 3.75.0 contains an information disclosure vulnerability that allows attackers to access files containing sensitive credentia...

Apr 25, 2025
CVE-2025-26730
7.5

This vulnerability exposes sensitive system information to unauthorized users in the WordPress Macro Calculator with Admin Email Optin & Data plugin. ...

Apr 15, 2025
CVE-2024-54279
7.5

This vulnerability in the WP-NERD Toolkit WordPress plugin exposes sensitive system information to unauthorized users. Attackers can access configurat...

Dec 16, 2024
CVE-2024-50528
7.5

This vulnerability in Stacks Mobile App Builder WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It aff...

Nov 4, 2024
CVE-2024-48024
7.5

The Keep Backup Daily WordPress plugin versions up to 2.0.7 expose sensitive system information to unauthorized users. This vulnerability allows attac...

Oct 17, 2024
CVE-2024-5735
7.5

A Full Path Disclosure vulnerability in the AdmirorFrames Joomla! extension allows unauthenticated attackers to retrieve the web root folder location....

Jun 28, 2024
CVE-2023-4237
7.3

This vulnerability in Ansible Automation Platform's ec2_key module exposes private keys in standard output when creating new keypairs. Attackers can e...

Oct 4, 2023
CVE-2024-25634
7.2

This vulnerability in alf.io ticket reservation system allows attackers to access email logs from other organizers' events through specially crafted r...

Feb 19, 2024
CVE-2025-47378
7.1

This cryptographic vulnerability in Qualcomm chipsets allows the High-Level Operating System (HLOS) to access the boot loader's certificate chain thro...

Mar 2, 2026
CVE-2025-47319
6.7

This vulnerability exposes internal Trusted Application (TA) communication APIs to the High-Level Operating System (HLOS), allowing unauthorized acces...

Dec 18, 2025
CVE-2025-14150
6.5

IBM webMethods Integration Server versions 10.15 through 11.1 can inadvertently expose sensitive user information in server responses. This informatio...

Feb 5, 2026
CVE-2025-68046
6.5

This vulnerability in the Contact Form & Lead Form Elementor Builder WordPress plugin allows unauthorized users to retrieve embedded sensitive data fr...

Jan 22, 2026
CVE-2025-67954
6.5

This vulnerability in the Dimitri Grassi Salon booking system WordPress plugin allows unauthorized attackers to retrieve embedded sensitive data from ...

Jan 22, 2026
CVE-2025-68551
6.5

This vulnerability in the Vikas Ratudi VPSUForm WordPress plugin allows unauthorized attackers to retrieve embedded sensitive data from affected syste...

Dec 23, 2025
CVE-2025-67546
6.5

This vulnerability in weDevs WP ERP plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects WordPress sites u...

Dec 18, 2025
CVE-2025-64270
6.5

This vulnerability in the Masteriyo LMS WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects all W...

Dec 18, 2025
CVE-2025-64272
6.5

This vulnerability in the GetResponse Email Marketing WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. ...

Dec 18, 2025
CVE-2025-49914
6.5

This vulnerability in the Restaurant Menu by MotoPress WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retr...

Dec 18, 2025

About CWE-497 (CWE-497)

Our database tracks 147 CVEs classified as CWE-497, with 6 rated critical and 35 rated high severity. The average CVSS score for CWE-497 vulnerabilities is 5.9.

External reference: View CWE-497 on MITRE CWE →

Monitor CWE-497 Vulnerabilities

Get alerted when new CWE-497 CVEs affect your infrastructure.

Start Monitoring Free