CWE-524: CWE-524

13
Total CVEs
1
Critical
1
High
5.6
Avg CVSS

Yearly Trend

2026
4
2025
6
2024
3

Top Affected Vendors

1 Hono 1
2 Vercel 1
3 Chamilo 1
4 Joinmastodon 1
5 Siemens 1
6 Shopware 1
7 Apple 1
8 Jetbrains 1
9 Axios Cache Interceptor 1
10 Workos 1

All CWE-524 CVEs (13)

CVE-2025-64762
9.1

The AuthKit library for Next.js versions 2.11.0 and below fails to apply anti-caching headers to authenticated responses. This allows session tokens t...

Nov 21, 2025
CVE-2024-27917
7.5

This vulnerability in Shopware allows session fixation attacks where cached 404 pages inadvertently expose session cookies to subsequent users. Attack...

Mar 6, 2024
CVE-2026-25540
6.5

Mastodon servers with AUTHORIZED_FETCH enabled are vulnerable to web cache poisoning where ActivityPub endpoints for pinned posts and featured hashtag...

Feb 4, 2026
CVE-2025-69202
6.5

Axios Cache Interceptor versions before 1.11.1 incorrectly cache responses without considering Authorization headers, allowing cached responses from o...

Dec 29, 2025
CVE-2025-57752
6.2

Next.js Image Optimization API routes have a cache key confusion vulnerability that could serve cached image responses to unauthorized users. This aff...

Aug 29, 2025
CVE-2025-9901
5.9

A vulnerability in libsoup's SoupCache ignores the HTTP Vary header when evaluating cached responses, allowing cached content to be incorrectly reused...

Sep 3, 2025
CVE-2025-69581
5.5

Chamilo LMS 1.11.2 fails to properly clear cached sensitive user data from the Social Network/personal_data endpoint after logout. This allows subsequ...

Jan 16, 2026
CVE-2026-24472
5.3

Hono web framework versions before 4.11.7 have a cache middleware vulnerability that improperly handles HTTP cache control directives. This allows pri...

Jan 27, 2026
CVE-2024-49580
5.3

The CVE-2024-49580 vulnerability in JetBrains Ktor's HttpCache Plugin involves improper caching that could allow unauthorized disclosure of cached HTT...

Oct 17, 2024
CVE-2024-41906
4.8

SINEC Traffic Analyzer versions before V2.0 have a vulnerability where the web service doesn't properly handle cacheable HTTP responses. This allows a...

Aug 13, 2024
CVE-2026-27205
4.3

Flask versions 3.1.2 and below have a cache vulnerability where accessing session keys with certain Python operators (like 'in') fails to set proper c...

Feb 21, 2026
CVE-2025-64696
3.3

The Brother iPrint&Scan Android app versions 6.13.7 and earlier improperly stores application files in an external cache directory accessible to other...

Dec 9, 2025
CVE-2025-43410
2.4

This vulnerability allows an attacker with physical access to a Mac to view deleted notes due to improper cache handling. It affects macOS users runni...

Dec 12, 2025

About CWE-524 (CWE-524)

Our database tracks 13 CVEs classified as CWE-524, with 1 rated critical and 1 rated high severity. The average CVSS score for CWE-524 vulnerabilities is 5.6.

External reference: View CWE-524 on MITRE CWE →

Monitor CWE-524 Vulnerabilities

Get alerted when new CWE-524 CVEs affect your infrastructure.

Start Monitoring Free