CWE-497: CWE-497

147
Total CVEs
6
Critical
35
High
5.9
Avg CVSS

Yearly Trend

2026
28
2025
100
2024
16
2023
2
2022
1

Top Affected Vendors

1 Ibm 14
2 Sap 4
3 Hcltech 3
4 Qualcomm 3
5 Apple 2
6 Canonical 2
7 Nagios 2
8 Sick 2
9 Zitadel 1
10 Themehunk 1

All CWE-497 CVEs (147)

CVE-2024-13998
6.5

Nagios XI versions before 2024R1.1.3 allow authenticated users to access sensitive user account information including API keys and password hashes, wh...

Nov 3, 2025
CVE-2024-53814
6.5

This CVE describes a broken access control vulnerability in the Analytify WordPress plugin that allows unauthorized users to access sensitive system i...

Dec 9, 2024
CVE-2025-36238
6.0

This vulnerability allows local administrators on IBM PowerVM systems to extract sensitive information from Virtual TPMs through specific PowerVM serv...

Feb 2, 2026
CVE-2025-0056
6.0

SAP GUI for Java stores user input locally on client PCs, creating a security vulnerability. Attackers with administrative privileges or access to the...

Jan 14, 2025
CVE-2024-52321
5.9

Multiple SHARP routers have an improper authentication vulnerability in their configuration backup function. Remote unauthenticated attackers can retr...

Dec 23, 2024
CVE-2024-6388
5.9

The Ubuntu Advantage Desktop Daemon before version 1.12 leaks Pro tokens to unprivileged users by passing them as plaintext arguments. This allows una...

Jun 27, 2024
CVE-2025-46747
5.7

An authenticated user without user-management permissions can enumerate other user accounts in affected systems. This information disclosure vulnerabi...

May 12, 2025
CVE-2025-43471
5.5

This macOS vulnerability allows malicious applications to bypass security checks and access sensitive user data. It affects macOS systems running vers...

Dec 12, 2025
CVE-2025-43406
5.5

This CVE describes a logic flaw in macOS that could allow malicious applications to access sensitive user data they shouldn't normally be able to reac...

Dec 12, 2025
CVE-2025-49419
5.5

This vulnerability in Foxit eSign for WordPress allows unauthorized users to retrieve embedded sensitive data from the plugin. It affects all WordPres...

Jun 6, 2025
CVE-2025-2598
5.5

The AWS CDK CLI prints AWS credentials to console output when used with credential plugins that return expiration properties. This exposes sensitive c...

Mar 21, 2025
CVE-2025-23382
5.5

Dell Secure Connect Gateway (SCG) 5.0 Appliance versions 5.26 expose sensitive system information to unauthorized actors. A high-privileged attacker w...

Mar 19, 2025
CVE-2024-11029
5.5

This vulnerability in FreeIPA's API audit mechanism causes administrative credentials to be logged in plaintext during installation. Anyone with acces...

Jan 15, 2025
CVE-2026-3075
5.3

This vulnerability in the Simple Ajax Chat WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve embedde...

Feb 23, 2026
CVE-2026-25023
5.3

This vulnerability in the ContestsWP contest-code-checker WordPress plugin exposes sensitive system information to unauthorized users. Attackers can r...

Feb 3, 2026
CVE-2026-24998
5.3

This vulnerability in the Hustle WordPress plugin allows unauthorized users to retrieve embedded sensitive data from popups and opt-in forms. It affec...

Feb 3, 2026
CVE-2023-37525
5.3

This vulnerability in HCL BigFix Compliance allows remote attackers to access sensitive files in the WEB-INF directory, potentially exposing Java clas...

Jan 28, 2026
CVE-2026-0853
5.3

Certain A-Plus Video Technologies NVR models expose sensitive device status information through an unauthenticated debug page. This allows remote atta...

Jan 12, 2026
CVE-2025-31051
5.3

This vulnerability in the Plant - Gardening & Houseplants WordPress theme exposes sensitive system information to unauthorized users. Attackers can re...

Jan 7, 2026
CVE-2025-34171
5.3

CasaOS versions up to 0.4.15 expose unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug i...

Jan 2, 2026
CVE-2025-62114
5.3

This vulnerability in the Download Media Library WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve e...

Dec 31, 2025
CVE-2025-68943
5.3

Gitea versions before 1.21.8 inadvertently disclose users' login times through the explore/users API endpoint. This information leakage vulnerability ...

Dec 26, 2025
CVE-2024-58320
5.3

An information disclosure vulnerability in Kentico Xperience allows unauthenticated attackers to access sensitive administration interface hostname de...

Dec 18, 2025
CVE-2025-67565
5.3

This vulnerability in the Rehub WordPress theme allows unauthorized users to retrieve embedded sensitive system information. It affects all WordPress ...

Dec 9, 2025
CVE-2025-67567
5.3

This vulnerability in the Sober WordPress theme allows unauthorized users to retrieve embedded sensitive data from the system. It affects all WordPres...

Dec 9, 2025
CVE-2025-67564
5.3

This vulnerability in Pixel Manager for WooCommerce exposes sensitive system information to unauthorized parties. It affects WordPress sites using thi...

Dec 9, 2025
CVE-2025-63009
5.3

This vulnerability in the WP Google Analytics Events WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrie...

Dec 9, 2025
CVE-2025-62735
5.3

This vulnerability in the WordPress User Spam Remover plugin allows unauthorized users to retrieve embedded sensitive system information. It affects a...

Dec 9, 2025
CVE-2025-62737
5.3

This vulnerability in the Image Cleanup WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all...

Dec 9, 2025
CVE-2025-36112
5.3

This vulnerability in IBM Sterling B2B Integrator and Sterling File Gateway allows unauthorized users to access sensitive server IP configuration info...

Nov 24, 2025
CVE-2025-66059
5.3

This vulnerability in Seriously Simple Podcasting WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It a...

Nov 21, 2025
CVE-2025-36160
5.3

IBM Concert versions 1.0.0 through 2.0.0 disclose sensitive server information via HTTP response headers. This information leakage could help attacker...

Nov 20, 2025
CVE-2025-13160
5.3

IQ-Support software by IQ Service International contains an information exposure vulnerability that allows unauthenticated remote attackers to access ...

Nov 14, 2025
CVE-2025-52616
5.3

HCL Unica 12.1.10 exposes sensitive system information that could help attackers plan targeted attacks. This affects organizations using HCL Unica 12....

Oct 12, 2025
CVE-2025-58579
5.3

This vulnerability allows unauthenticated attackers to query an endpoint without proper authentication, enabling user enumeration attacks. It affects ...

Oct 6, 2025
CVE-2025-60092
5.3

This vulnerability in Shahjada Download Manager WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affec...

Sep 26, 2025
CVE-2025-59582
5.3

This vulnerability in the WordPress Ajax Load More plugin allows unauthorized users to retrieve embedded sensitive data from affected websites. It aff...

Sep 22, 2025
CVE-2025-58015
5.3

This vulnerability in the Ays Pro Quiz Maker WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affect...

Sep 22, 2025
CVE-2025-57888
5.3

This vulnerability in the NooTheme Jobmonster WordPress theme allows unauthorized users to retrieve embedded sensitive data from the system. It affect...

Aug 22, 2025
CVE-2025-54736
5.3

The NordicMade Savoy WordPress theme exposes sensitive system information to unauthorized users, allowing attackers to retrieve embedded sensitive dat...

Aug 14, 2025
CVE-2025-53364
5.3

Parse Server's GraphQL API exposed schema metadata without authentication in versions 5.3.0 through 7.5.2 and 8.0.0 through 8.2.1. This allows attacke...

Jul 10, 2025
CVE-2025-53211
5.3

This vulnerability in Roland Beaussant Audio Editor & Recorder allows unauthorized users to retrieve embedded sensitive system information. It affects...

Jun 27, 2025
CVE-2025-39394
5.3

This vulnerability in the AnalyticsWP WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects all ver...

May 19, 2025
CVE-2025-30011
5.3

An unauthenticated attacker can exploit a deprecated Java applet component in SAP SRM's Live Auction Cockpit to send malicious requests that disclose ...

May 13, 2025
CVE-2025-47540
5.3

This vulnerability in weDevs weMail WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all weM...

May 7, 2025
CVE-2024-10940
5.3

This vulnerability in langchain-core allows unauthorized users to read arbitrary files from the host file system by exploiting prompt templates. It af...

Mar 20, 2025
CVE-2024-40706
5.3

IBM InfoSphere Information Server 11.7 exposes sensitive version information to remote users, which could be used for reconnaissance in targeted attac...

Jan 24, 2025
CVE-2024-45640
5.3

IBM Security ReaQta 3.12 discloses sensitive information in HTTP responses that could aid attackers in reconnaissance or further exploitation. This af...

Jan 7, 2025
CVE-2024-32732
5.3

CVE-2024-32732 is an information disclosure vulnerability in SAP BusinessObjects Business Intelligence platform that allows attackers to access restri...

Dec 10, 2024
CVE-2024-25035
5.3

IBM Cognos Controller versions 11.0.0 and 11.0.1 expose server details through an information disclosure vulnerability. This allows attackers to gathe...

Dec 3, 2024

About CWE-497 (CWE-497)

Our database tracks 147 CVEs classified as CWE-497, with 6 rated critical and 35 rated high severity. The average CVSS score for CWE-497 vulnerabilities is 5.9.

External reference: View CWE-497 on MITRE CWE →

Monitor CWE-497 Vulnerabilities

Get alerted when new CWE-497 CVEs affect your infrastructure.

Start Monitoring Free