CWE-497: CWE-497
Yearly Trend
Top Affected Vendors
All CWE-497 CVEs (147)
Nagios XI versions before 2024R1.1.3 allow authenticated users to access sensitive user account information including API keys and password hashes, wh...
Nov 3, 2025This CVE describes a broken access control vulnerability in the Analytify WordPress plugin that allows unauthorized users to access sensitive system i...
Dec 9, 2024This vulnerability allows local administrators on IBM PowerVM systems to extract sensitive information from Virtual TPMs through specific PowerVM serv...
Feb 2, 2026SAP GUI for Java stores user input locally on client PCs, creating a security vulnerability. Attackers with administrative privileges or access to the...
Jan 14, 2025Multiple SHARP routers have an improper authentication vulnerability in their configuration backup function. Remote unauthenticated attackers can retr...
Dec 23, 2024The Ubuntu Advantage Desktop Daemon before version 1.12 leaks Pro tokens to unprivileged users by passing them as plaintext arguments. This allows una...
Jun 27, 2024An authenticated user without user-management permissions can enumerate other user accounts in affected systems. This information disclosure vulnerabi...
May 12, 2025This macOS vulnerability allows malicious applications to bypass security checks and access sensitive user data. It affects macOS systems running vers...
Dec 12, 2025This CVE describes a logic flaw in macOS that could allow malicious applications to access sensitive user data they shouldn't normally be able to reac...
Dec 12, 2025This vulnerability in Foxit eSign for WordPress allows unauthorized users to retrieve embedded sensitive data from the plugin. It affects all WordPres...
Jun 6, 2025The AWS CDK CLI prints AWS credentials to console output when used with credential plugins that return expiration properties. This exposes sensitive c...
Mar 21, 2025Dell Secure Connect Gateway (SCG) 5.0 Appliance versions 5.26 expose sensitive system information to unauthorized actors. A high-privileged attacker w...
Mar 19, 2025This vulnerability in FreeIPA's API audit mechanism causes administrative credentials to be logged in plaintext during installation. Anyone with acces...
Jan 15, 2025This vulnerability in the Simple Ajax Chat WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve embedde...
Feb 23, 2026This vulnerability in the ContestsWP contest-code-checker WordPress plugin exposes sensitive system information to unauthorized users. Attackers can r...
Feb 3, 2026This vulnerability in the Hustle WordPress plugin allows unauthorized users to retrieve embedded sensitive data from popups and opt-in forms. It affec...
Feb 3, 2026This vulnerability in HCL BigFix Compliance allows remote attackers to access sensitive files in the WEB-INF directory, potentially exposing Java clas...
Jan 28, 2026Certain A-Plus Video Technologies NVR models expose sensitive device status information through an unauthenticated debug page. This allows remote atta...
Jan 12, 2026This vulnerability in the Plant - Gardening & Houseplants WordPress theme exposes sensitive system information to unauthorized users. Attackers can re...
Jan 7, 2026CasaOS versions up to 0.4.15 expose unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug i...
Jan 2, 2026This vulnerability in the Download Media Library WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve e...
Dec 31, 2025Gitea versions before 1.21.8 inadvertently disclose users' login times through the explore/users API endpoint. This information leakage vulnerability ...
Dec 26, 2025An information disclosure vulnerability in Kentico Xperience allows unauthenticated attackers to access sensitive administration interface hostname de...
Dec 18, 2025This vulnerability in the Rehub WordPress theme allows unauthorized users to retrieve embedded sensitive system information. It affects all WordPress ...
Dec 9, 2025This vulnerability in the Sober WordPress theme allows unauthorized users to retrieve embedded sensitive data from the system. It affects all WordPres...
Dec 9, 2025This vulnerability in Pixel Manager for WooCommerce exposes sensitive system information to unauthorized parties. It affects WordPress sites using thi...
Dec 9, 2025This vulnerability in the WP Google Analytics Events WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrie...
Dec 9, 2025This vulnerability in the WordPress User Spam Remover plugin allows unauthorized users to retrieve embedded sensitive system information. It affects a...
Dec 9, 2025This vulnerability in the Image Cleanup WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all...
Dec 9, 2025This vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway allows unauthorized users to access sensitive server IP configuration info...
Nov 24, 2025This vulnerability in Seriously Simple Podcasting WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It a...
Nov 21, 2025IBM Concert versions 1.0.0 through 2.0.0 disclose sensitive server information via HTTP response headers. This information leakage could help attacker...
Nov 20, 2025IQ-Support software by IQ Service International contains an information exposure vulnerability that allows unauthenticated remote attackers to access ...
Nov 14, 2025HCL Unica 12.1.10 exposes sensitive system information that could help attackers plan targeted attacks. This affects organizations using HCL Unica 12....
Oct 12, 2025This vulnerability allows unauthenticated attackers to query an endpoint without proper authentication, enabling user enumeration attacks. It affects ...
Oct 6, 2025This vulnerability in Shahjada Download Manager WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affec...
Sep 26, 2025This vulnerability in the WordPress Ajax Load More plugin allows unauthorized users to retrieve embedded sensitive data from affected websites. It aff...
Sep 22, 2025This vulnerability in the Ays Pro Quiz Maker WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affect...
Sep 22, 2025This vulnerability in the NooTheme Jobmonster WordPress theme allows unauthorized users to retrieve embedded sensitive data from the system. It affect...
Aug 22, 2025The NordicMade Savoy WordPress theme exposes sensitive system information to unauthorized users, allowing attackers to retrieve embedded sensitive dat...
Aug 14, 2025Parse Server's GraphQL API exposed schema metadata without authentication in versions 5.3.0 through 7.5.2 and 8.0.0 through 8.2.1. This allows attacke...
Jul 10, 2025This vulnerability in Roland Beaussant Audio Editor & Recorder allows unauthorized users to retrieve embedded sensitive system information. It affects...
Jun 27, 2025This vulnerability in the AnalyticsWP WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects all ver...
May 19, 2025An unauthenticated attacker can exploit a deprecated Java applet component in SAP SRM's Live Auction Cockpit to send malicious requests that disclose ...
May 13, 2025This vulnerability in weDevs weMail WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all weM...
May 7, 2025This vulnerability in langchain-core allows unauthorized users to read arbitrary files from the host file system by exploiting prompt templates. It af...
Mar 20, 2025IBM InfoSphere Information Server 11.7 exposes sensitive version information to remote users, which could be used for reconnaissance in targeted attac...
Jan 24, 2025IBM Security ReaQta 3.12 discloses sensitive information in HTTP responses that could aid attackers in reconnaissance or further exploitation. This af...
Jan 7, 2025CVE-2024-32732 is an information disclosure vulnerability in SAP BusinessObjects Business Intelligence platform that allows attackers to access restri...
Dec 10, 2024IBM Cognos Controller versions 11.0.0 and 11.0.1 expose server details through an information disclosure vulnerability. This allows attackers to gathe...
Dec 3, 2024About CWE-497 (CWE-497)
Our database tracks 147 CVEs classified as CWE-497, with 6 rated critical and 35 rated high severity. The average CVSS score for CWE-497 vulnerabilities is 5.9.
External reference: View CWE-497 on MITRE CWE →
Monitor CWE-497 Vulnerabilities
Get alerted when new CWE-497 CVEs affect your infrastructure.
Start Monitoring Free