CWE-598: CWE-598
Yearly Trend
Top Affected Vendors
All CWE-598 CVEs (28)
This vulnerability in Broadcom DX NetOps Spectrum exposes sensitive information through query strings in GET requests, allowing attackers to hijack us...
Jan 12, 2026This vulnerability allows unauthenticated attackers to create arbitrary user accounts in MLflow deployments, bypassing all authentication requirements...
Nov 16, 2023CVE-2021-36328 is a SQL injection vulnerability in Dell EMC Streaming Data Platform that allows remote attackers to execute arbitrary SQL commands. Th...
Nov 30, 2021Dell EMC AppSync versions 3.9 to 4.3 transmit sensitive session information via GET request query strings, which can be intercepted by adjacent attack...
Jan 21, 2022This vulnerability in DirectAdmin v1.680 allows unauthenticated attackers to manipulate the login page layout and replace it with malicious content vi...
Oct 3, 2025Dell PowerScale OneFS versions 8.2.2 through 9.1.0.x have a vulnerability where sensitive data can be exposed through GET requests containing sensitiv...
Aug 16, 2021CVE-2026-23846 is a sensitive information exposure vulnerability in Tugtainer where passwords are transmitted via URL query parameters instead of secu...
Jan 19, 2026Dell EMC CloudLink versions 7.1.3 and earlier expose authentication tokens in GET request URLs, which can be logged by reverse proxies and servers. At...
May 26, 2022The Mojave Inverter uses HTTP GET requests to transmit sensitive information, potentially exposing credentials or configuration data in URLs, logs, or...
Feb 13, 2025This vulnerability in Optimizely Configured Commerce exposes session tokens in URL parameters, allowing attackers to hijack authenticated user session...
Jan 4, 2025This vulnerability exposes CSRF tokens in URL query parameters in Checkmk monitoring software, allowing attackers to steal these tokens. Attackers can...
Oct 14, 2024CVE-2024-23766 is an unauthenticated denial-of-service vulnerability in HMS Anybus X-Gateway AB7832-F 3 devices. Attackers can send a simple GET reque...
Jun 26, 2024This vulnerability in Secomea GateManager's LMM API allows system administrators to hijack connections by exposing sensitive information through query...
May 4, 2022This vulnerability in Key Systems Inc Global Facilities Management Software allows remote attackers to access sensitive information through the sid qu...
Feb 20, 2026IBM i operating systems (versions 7.2-7.6) have an information disclosure vulnerability in the database plan cache implementation. Authenticated users...
Nov 19, 2025The Trivision Camera NC227WF v5.8.0 transmits passwords in URL query strings, exposing authentication credentials to network eavesdroppers and interme...
Feb 27, 2025HCL ZIE for Web v16 transmits sensitive session tokens and authentication identifiers in URL query parameters, allowing attackers who can access netwo...
Feb 23, 2026IBM TXSeries for Multiplatforms 10.1 has an information disclosure vulnerability where sensitive data in HTTP GET query strings can be intercepted via...
Nov 1, 2024This vulnerability exposes password hashes and session tokens in URLs due to improper use of GET requests with sensitive data in the 130.8005 TCP/IP G...
Feb 13, 2025QuickCMS transmits user credentials via GET requests instead of POST, exposing passwords and login information in browser history and server logs. Thi...
Aug 28, 2025An authenticated arbitrary file download vulnerability in Mccms v2.7.0 allows attackers with admin access to download any file from the server via a c...
Jul 14, 2025This vulnerability allows attackers to steal authentication tokens when they are passed in URL query parameters, potentially enabling session hijackin...
Jan 15, 2026This vulnerability exposes authentication credentials transmitted via URL parameters, which can be unintentionally stored in server logs, browser hist...
Oct 6, 2025This vulnerability in Siemens SIPROTEC 5 devices exposes session identifiers in URL requests, potentially allowing attackers to retrieve sensitive ses...
Jul 8, 2025This vulnerability in Perplexity AI GPT-4 allows remote attackers to access sensitive information through GET parameters. It affects systems running v...
Sep 17, 2025IBM InfoSphere Information Server 11.7 exposes sensitive information in URLs, potentially revealing system details that could aid attackers in reconna...
Jun 30, 2024Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection, allowing attackers to capture these tokens via browser history, logs, ...
Feb 18, 2025This vulnerability in Tridium Niagara Framework and Enterprise Security allows attackers to inject parameters through GET requests with sensitive quer...
May 22, 2025About CWE-598 (CWE-598)
Our database tracks 28 CVEs classified as CWE-598, with 2 rated critical and 12 rated high severity. The average CVSS score for CWE-598 vulnerabilities is 6.7.
External reference: View CWE-598 on MITRE CWE →
Monitor CWE-598 Vulnerabilities
Get alerted when new CWE-598 CVEs affect your infrastructure.
Start Monitoring Free