CWE-497: CWE-497
Yearly Trend
Top Affected Vendors
All CWE-497 CVEs (147)
This CVE describes an information disclosure vulnerability in GitLab EE where an unauthenticated user can read some information about merge requests i...
Nov 26, 2024This vulnerability in MasterStudy LMS WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all v...
Oct 22, 2025This vulnerability in the WordPress Custom Field Template plugin allows unauthorized users to retrieve embedded sensitive data from affected websites....
Dec 9, 2025Brocade SANnav versions before 2.4.0a log passwords and PBE keys in local server audit logs under specific conditions. This allows server administrato...
Jul 10, 2025CVE-2026-24314 is an information disclosure vulnerability in SAP S/4HANA's Manage Payment Media component that allows authenticated users to access re...
Feb 24, 2026This vulnerability in the Fraud Prevention for WooCommerce WordPress plugin exposes sensitive system information to unauthorized users. Attackers can ...
Jan 23, 2026This vulnerability in the REHub Framework WordPress plugin allows unauthorized users to retrieve embedded sensitive data from affected systems. It aff...
Jan 22, 2026CVE-2026-22915 allows attackers with low privileges to read files from specific directories on affected devices, potentially exposing sensitive inform...
Jan 15, 2026This CVE describes a clickjacking vulnerability in the PDF Viewer component of Mozilla products that could allow information disclosure. Attackers cou...
Jan 13, 2026The BoomDevs WordPress Coming Soon Plugin versions up to 1.0.4 expose sensitive system information to unauthorized users. This vulnerability allows at...
Dec 31, 2025This vulnerability in the Direct Payments WP WordPress plugin allows unauthorized users to retrieve embedded sensitive data. It affects all versions u...
Dec 31, 2025The Post Video Players WordPress plugin exposes sensitive system information to unauthorized users. This vulnerability allows attackers to retrieve em...
Dec 31, 2025This vulnerability in the Poptics WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all WordP...
Dec 30, 2025This vulnerability in the Roxnor PopupKit WordPress plugin allows unauthorized users to retrieve embedded sensitive data from affected websites. It af...
Dec 30, 2025This vulnerability in HappyDevs TempTool WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve embedded ...
Dec 21, 2025This vulnerability in the SendPulse Email Marketing Newsletter WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the...
Dec 16, 2025ZITADEL versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users regardless of th...
Dec 11, 2025This vulnerability in the WordPress Portfolio and Projects plugin allows unauthorized users to retrieve embedded sensitive system information. It affe...
Dec 9, 2025This vulnerability in the WordPress Download Manager plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects ...
Dec 9, 2025This vulnerability in the WP Hotel Booking WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects al...
Dec 9, 2025Primakon Pi Portal 1.0.18's /api/v2/users endpoint lacks proper access controls, allowing any authenticated user to retrieve a complete list of all re...
Nov 25, 2025This vulnerability in the Uncanny Automator WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects...
Nov 21, 2025This vulnerability in the WooCommerce Ultimate Points And Rewards plugin exposes sensitive system information to unauthorized users. Attackers can ret...
Nov 13, 2025IBM OpenPages 9.0 and 9.1 has insecure REST endpoints that allow authenticated users to access system metadata beyond their intended permissions. This...
Nov 12, 2025This vulnerability in the SUMO Affiliates Pro WordPress plugin allows unauthorized users to retrieve embedded sensitive data, such as configuration de...
Oct 29, 2025This vulnerability in Page Manager for Elementor WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve e...
Sep 26, 2025This vulnerability in the Social Pug WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects all Word...
Sep 22, 2025This vulnerability in the WPeMatico RSS Feed Fetcher WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It ...
Sep 22, 2025The WP System Information WordPress plugin versions up to 1.5 expose sensitive system data to unauthorized users. This vulnerability allows attackers ...
Sep 22, 2025IBM Lakehouse (watsonx.data 2.2) exposes sensitive server component version information to authenticated users. This information disclosure vulnerabil...
Sep 18, 2025This vulnerability in IBM DevOps Deploy/UrbanCode Deploy allows authenticated users to access sensitive configuration information they shouldn't have ...
Sep 2, 2025IBM OpenPages 9.0 has a vulnerability where authenticated users can access sensitive workflow configuration and internal state information through ins...
Jul 9, 2025This vulnerability in Essential Addons for Elementor WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrie...
Apr 16, 2025HCL Traveler for Windows exposes internal file paths in error messages or debug logs, potentially revealing sensitive directory structures. This affec...
Apr 3, 2025The WordPress Our Team Members plugin versions up to 2.2 expose sensitive system information to unauthorized users. This vulnerability allows attacker...
Apr 1, 2025The Bowo System Dashboard WordPress plugin exposes sensitive system information to unauthorized users due to misconfigured access controls. This vulne...
Feb 25, 2025This vulnerability in Synapse's Sliding Sync feature allows users who have left a room to still receive partial room state updates, potentially exposi...
Dec 3, 2024This vulnerability in NSD570 allows any authenticated user to access all device logs, potentially exposing login information with timestamps. This aff...
Nov 26, 2024This vulnerability in IBM Concert Software allows authenticated users to access sensitive information that could facilitate further attacks. It affect...
Nov 19, 2024This vulnerability in IBM Jazz Reporting Service allows authenticated users on the same network to access sensitive information from other projects on...
Feb 4, 2026This vulnerability in IBM Aspera Faspex 5 allows authenticated users to enumerate sensitive information by discovering package identifiers. It affects...
Dec 26, 2025An authenticated administrator in Palo Alto Networks PAN-OS software can view session tokens of users logged into the firewall web UI, potentially ena...
Oct 9, 2025CVE-2025-13651 is an information disclosure vulnerability in Microcom ZeusWeb version 6.1.31 that allows unauthorized attackers to fingerprint the web...
Feb 11, 2026This vulnerability in Yokogawa's FAST/TOOLS software exposes physical file paths on web pages, potentially revealing sensitive system information. Att...
Feb 9, 2026CVE-2025-59098 is an unauthenticated, unencrypted TCP socket vulnerability in dormakaba Access Manager that broadcasts sensitive debug information inc...
Jan 26, 2026This vulnerability allows attackers to access sensitive files containing clear-text credentials and valuable information on charging systems. It affec...
Jan 7, 2026This vulnerability in Sharp Display Solutions projectors allows unauthorized attackers to access the HTTP server interface and execute arbitrary actio...
Dec 22, 2025About CWE-497 (CWE-497)
Our database tracks 147 CVEs classified as CWE-497, with 6 rated critical and 35 rated high severity. The average CVSS score for CWE-497 vulnerabilities is 5.9.
External reference: View CWE-497 on MITRE CWE →
Monitor CWE-497 Vulnerabilities
Get alerted when new CWE-497 CVEs affect your infrastructure.
Start Monitoring Free