CWE-497: CWE-497

147
Total CVEs
6
Critical
35
High
5.9
Avg CVSS

Yearly Trend

2026
28
2025
100
2024
16
2023
2
2022
1

Top Affected Vendors

1 Ibm 14
2 Sap 4
3 Hcltech 3
4 Qualcomm 3
5 Apple 2
6 Canonical 2
7 Nagios 2
8 Sick 2
9 Zitadel 1
10 Themehunk 1

All CWE-497 CVEs (147)

CVE-2024-10240
5.3

This CVE describes an information disclosure vulnerability in GitLab EE where an unauthenticated user can read some information about merge requests i...

Nov 26, 2024
CVE-2025-59575
5.0

This vulnerability in MasterStudy LMS WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all v...

Oct 22, 2025
CVE-2025-63058
4.4

This vulnerability in the WordPress Custom Field Template plugin allows unauthorized users to retrieve embedded sensitive data from affected websites....

Dec 9, 2025
CVE-2025-6390
4.4

Brocade SANnav versions before 2.4.0a log passwords and PBE keys in local server audit logs under specific conditions. This allows server administrato...

Jul 10, 2025
CVE-2026-24314
4.3

CVE-2026-24314 is an information disclosure vulnerability in SAP S/4HANA's Manage Payment Media component that allows authenticated users to access re...

Feb 24, 2026
CVE-2026-24553
4.3

This vulnerability in the Fraud Prevention for WooCommerce WordPress plugin exposes sensitive system information to unauthorized users. Attackers can ...

Jan 23, 2026
CVE-2025-63051
4.3

This vulnerability in the REHub Framework WordPress plugin allows unauthorized users to retrieve embedded sensitive data from affected systems. It aff...

Jan 22, 2026
CVE-2026-22915
4.3

CVE-2026-22915 allows attackers with low privileges to read files from specific directories on affected devices, potentially exposing sensitive inform...

Jan 15, 2026
CVE-2026-0887
4.3

This CVE describes a clickjacking vulnerability in the PDF Viewer component of Mozilla products that could allow information disclosure. Attackers cou...

Jan 13, 2026
CVE-2025-62083
4.3

The BoomDevs WordPress Coming Soon Plugin versions up to 1.0.4 expose sensitive system information to unauthorized users. This vulnerability allows at...

Dec 31, 2025
CVE-2025-49340
4.3

This vulnerability in the Direct Payments WP WordPress plugin allows unauthorized users to retrieve embedded sensitive data. It affects all versions u...

Dec 31, 2025
CVE-2025-62143
4.3

The Post Video Players WordPress plugin exposes sensitive system information to unauthorized users. This vulnerability allows attackers to retrieve em...

Dec 31, 2025
CVE-2025-69025
4.3

This vulnerability in the Poptics WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects all WordP...

Dec 30, 2025
CVE-2025-69026
4.3

This vulnerability in the Roxnor PopupKit WordPress plugin allows unauthorized users to retrieve embedded sensitive data from affected websites. It af...

Dec 30, 2025
CVE-2025-62955
4.3

This vulnerability in HappyDevs TempTool WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve embedded ...

Dec 21, 2025
CVE-2025-67948
4.3

This vulnerability in the SendPulse Email Marketing Newsletter WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the...

Dec 16, 2025
CVE-2025-67717
4.3

ZITADEL versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users regardless of th...

Dec 11, 2025
CVE-2025-67470
4.3

This vulnerability in the WordPress Portfolio and Projects plugin allows unauthorized users to retrieve embedded sensitive system information. It affe...

Dec 9, 2025
CVE-2025-63070
4.3

This vulnerability in the WordPress Download Manager plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects ...

Dec 9, 2025
CVE-2025-63013
4.3

This vulnerability in the WP Hotel Booking WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects al...

Dec 9, 2025
CVE-2025-64061
4.3

Primakon Pi Portal 1.0.18's /api/v2/users endpoint lacks proper access controls, allowing any authenticated user to retrieve a complete list of all re...

Nov 25, 2025
CVE-2025-66056
4.3

This vulnerability in the Uncanny Automator WordPress plugin allows unauthorized users to retrieve embedded sensitive data from the system. It affects...

Nov 21, 2025
CVE-2025-64267
4.3

This vulnerability in the WooCommerce Ultimate Points And Rewards plugin exposes sensitive system information to unauthorized users. Attackers can ret...

Nov 13, 2025
CVE-2025-27368
4.3

IBM OpenPages 9.0 and 9.1 has insecure REST endpoints that allow authenticated users to access system metadata beyond their intended permissions. This...

Nov 12, 2025
CVE-2025-64228
4.3

This vulnerability in the SUMO Affiliates Pro WordPress plugin allows unauthorized users to retrieve embedded sensitive data, such as configuration de...

Oct 29, 2025
CVE-2025-60167
4.3

This vulnerability in Page Manager for Elementor WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrieve e...

Sep 26, 2025
CVE-2025-58007
4.3

This vulnerability in the Social Pug WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It affects all Word...

Sep 22, 2025
CVE-2025-57937
4.3

This vulnerability in the WPeMatico RSS Feed Fetcher WordPress plugin allows unauthorized users to retrieve embedded sensitive system information. It ...

Sep 22, 2025
CVE-2025-57916
4.3

The WP System Information WordPress plugin versions up to 1.5 expose sensitive system data to unauthorized users. This vulnerability allows attackers ...

Sep 22, 2025
CVE-2025-36146
4.3

IBM Lakehouse (watsonx.data 2.2) exposes sensitive server component version information to authenticated users. This information disclosure vulnerabil...

Sep 18, 2025
CVE-2025-36162
4.3

This vulnerability in IBM DevOps Deploy/UrbanCode Deploy allows authenticated users to access sensitive configuration information they shouldn't have ...

Sep 2, 2025
CVE-2025-2670
4.3

IBM OpenPages 9.0 has a vulnerability where authenticated users can access sensitive workflow configuration and internal state information through ins...

Jul 9, 2025
CVE-2025-39589
4.3

This vulnerability in Essential Addons for Elementor WordPress plugin exposes sensitive system information to unauthorized users. Attackers can retrie...

Apr 16, 2025
CVE-2025-0278
4.3

HCL Traveler for Windows exposes internal file paths in error messages or debug logs, potentially revealing sensitive directory structures. This affec...

Apr 3, 2025
CVE-2025-30802
4.3

The WordPress Our Team Members plugin versions up to 2.2 expose sensitive system information to unauthorized users. This vulnerability allows attacker...

Apr 1, 2025
CVE-2025-26911
4.3

The Bowo System Dashboard WordPress plugin exposes sensitive system information to unauthorized users due to misconfigured access controls. This vulne...

Feb 25, 2025
CVE-2024-53867
4.3

This vulnerability in Synapse's Sliding Sync feature allows users who have left a room to still receive partial room state updates, potentially exposi...

Dec 3, 2024
CVE-2024-9929
4.3

This vulnerability in NSD570 allows any authenticated user to access all device logs, potentially exposing login information with timestamps. This aff...

Nov 26, 2024
CVE-2024-37070
4.3

This vulnerability in IBM Concert Software allows authenticated users to access sensitive information that could facilitate further attacks. It affect...

Nov 19, 2024
CVE-2025-27550
3.5

This vulnerability in IBM Jazz Reporting Service allows authenticated users on the same network to access sensitive information from other projects on...

Feb 4, 2026
CVE-2025-36229
3.1

This vulnerability in IBM Aspera Faspex 5 allows authenticated users to enumerate sensitive information by discovering package identifiers. It affects...

Dec 26, 2025
CVE-2025-4614
2.7

An authenticated administrator in Palo Alto Networks PAN-OS software can view session tokens of users logged into the firewall web UI, potentially ena...

Oct 9, 2025
CVE-2025-13651
N/A

CVE-2025-13651 is an information disclosure vulnerability in Microcom ZeusWeb version 6.1.31 that allows unauthorized attackers to fingerprint the web...

Feb 11, 2026
CVE-2025-66599
N/A

This vulnerability in Yokogawa's FAST/TOOLS software exposes physical file paths on web pages, potentially revealing sensitive system information. Att...

Feb 9, 2026
CVE-2025-59098
N/A

CVE-2025-59098 is an unauthenticated, unencrypted TCP socket vulnerability in dormakaba Access Manager that broadcasts sensitive debug information inc...

Jan 26, 2026
CVE-2026-22537
N/A

This vulnerability allows attackers to access sensitive files containing clear-text credentials and valuable information on charging systems. It affec...

Jan 7, 2026
CVE-2025-11545
N/A

This vulnerability in Sharp Display Solutions projectors allows unauthorized attackers to access the HTTP server interface and execute arbitrary actio...

Dec 22, 2025

About CWE-497 (CWE-497)

Our database tracks 147 CVEs classified as CWE-497, with 6 rated critical and 35 rated high severity. The average CVSS score for CWE-497 vulnerabilities is 5.9.

External reference: View CWE-497 on MITRE CWE →

Monitor CWE-497 Vulnerabilities

Get alerted when new CWE-497 CVEs affect your infrastructure.

Start Monitoring Free