CWE-598: CWE-598

28
Total CVEs
2
Critical
12
High
6.7
Avg CVSS

Yearly Trend

2026
5
2025
13
2024
4
2023
1
2022
3

Top Affected Vendors

1 Dell 4
2 Ibm 3
3 Sick 2
4 Secomea 1
5 Keystorage 1
6 Broadcom 1
7 Quenary 1
8 Webkul 1
9 Lfprojects 1
10 Opensolution 1

All CWE-598 CVEs (28)

CVE-2025-69270
9.8

This vulnerability in Broadcom DX NetOps Spectrum exposes sensitive information through query strings in GET requests, allowing attackers to hijack us...

Jan 12, 2026
CVE-2023-6014
9.8

This vulnerability allows unauthenticated attackers to create arbitrary user accounts in MLflow deployments, bypassing all authentication requirements...

Nov 16, 2023
CVE-2021-36328
8.8

CVE-2021-36328 is a SQL injection vulnerability in Dell EMC Streaming Data Platform that allows remote attackers to execute arbitrary SQL commands. Th...

Nov 30, 2021
CVE-2022-22551
8.3

Dell EMC AppSync versions 3.9 to 4.3 transmit sensitive session information via GET request query strings, which can be intercepted by adjacent attack...

Jan 21, 2022
CVE-2025-56551
8.2

This vulnerability in DirectAdmin v1.680 allows unauthenticated attackers to manipulate the login page layout and replace it with malicious content vi...

Oct 3, 2025
CVE-2021-21594
8.2

Dell PowerScale OneFS versions 8.2.2 through 9.1.0.x have a vulnerability where sensitive data can be exposed through GET requests containing sensitiv...

Aug 16, 2021
CVE-2026-23846
8.1

CVE-2026-23846 is a sensitive information exposure vulnerability in Tugtainer where passwords are transmitted via URL query parameters instead of secu...

Jan 19, 2026
CVE-2022-24414
7.6

Dell EMC CloudLink versions 7.1.3 and earlier expose authentication tokens in GET request URLs, which can be logged by reverse proxies and servers. At...

May 26, 2022
CVE-2025-26473
7.5

The Mojave Inverter uses HTTP GET requests to transmit sensitive information, potentially exposing credentials or configuration data in URLs, logs, or...

Feb 13, 2025
CVE-2025-22387
7.5

This vulnerability in Optimizely Configured Commerce exposes session tokens in URL parameters, allowing attackers to hijack authenticated user session...

Jan 4, 2025
CVE-2024-38863
7.5

This vulnerability exposes CSRF tokens in URL query parameters in Checkmk monitoring software, allowing attackers to steal these tokens. Attackers can...

Oct 14, 2024
CVE-2024-23766
7.5

CVE-2024-23766 is an unauthenticated denial-of-service vulnerability in HMS Anybus X-Gateway AB7832-F 3 devices. Attackers can send a simple GET reque...

Jun 26, 2024
CVE-2022-25787
7.5

This vulnerability in Secomea GateManager's LMM API allows system administrators to hijack connections by exposing sensitive information through query...

May 4, 2022
CVE-2026-26721
7.1

This vulnerability in Key Systems Inc Global Facilities Management Software allows remote attackers to access sensitive information through the sid qu...

Feb 20, 2026
CVE-2025-36371
6.5

IBM i operating systems (versions 7.2-7.6) have an information disclosure vulnerability in the database plan cache implementation. Authenticated users...

Nov 19, 2025
CVE-2025-1738
6.2

The Trivision Camera NC227WF v5.8.0 transmits passwords in URL query strings, exposing authentication credentials to network eavesdroppers and interme...

Feb 27, 2025
CVE-2025-59873
5.9

HCL ZIE for Web v16 transmits sensitive session tokens and authentication identifiers in URL query parameters, allowing attackers who can access netwo...

Feb 23, 2026
CVE-2024-41738
5.9

IBM TXSeries for Multiplatforms 10.1 has an information disclosure vulnerability where sensitive data in HTTP GET query strings can be intercepted via...

Nov 1, 2024
CVE-2024-12012
5.7

This vulnerability exposes password hashes and session tokens in URLs due to improper use of GET requests with sensitive data in the 130.8005 TCP/IP G...

Feb 13, 2025
CVE-2025-54542
5.5

QuickCMS transmits user credentials via GET requests instead of POST, exposing passwords and login information in browser history and server logs. Thi...

Aug 28, 2025
CVE-2025-51651
5.5

An authenticated arbitrary file download vulnerability in Mccms v2.7.0 allows attackers with admin access to download any file from the server via a c...

Jul 14, 2025
CVE-2026-22644
5.3

This vulnerability allows attackers to steal authentication tokens when they are passed in URL query parameters, potentially enabling session hijackin...

Jan 15, 2026
CVE-2025-58584
5.3

This vulnerability exposes authentication credentials transmitted via URL parameters, which can be unintentionally stored in server logs, browser hist...

Oct 6, 2025
CVE-2025-40742
5.3

This vulnerability in Siemens SIPROTEC 5 devices exposes session identifiers in URL requests, potentially allowing attackers to retrieve sensitive ses...

Jul 8, 2025
CVE-2025-50709
4.3

This vulnerability in Perplexity AI GPT-4 allows remote attackers to access sensitive information through GET parameters. It affects systems running v...

Sep 17, 2025
CVE-2023-50954
4.3

IBM InfoSphere Information Server 11.7 exposes sensitive information in URLs, potentially revealing system details that could aid attackers in reconna...

Jun 30, 2024
CVE-2025-26058
4.2

Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection, allowing attackers to capture these tokens via browser history, logs, ...

Feb 18, 2025
CVE-2025-3943
4.1

This vulnerability in Tridium Niagara Framework and Enterprise Security allows attackers to inject parameters through GET requests with sensitive quer...

May 22, 2025

About CWE-598 (CWE-598)

Our database tracks 28 CVEs classified as CWE-598, with 2 rated critical and 12 rated high severity. The average CVSS score for CWE-598 vulnerabilities is 6.7.

External reference: View CWE-598 on MITRE CWE →

Monitor CWE-598 Vulnerabilities

Get alerted when new CWE-598 CVEs affect your infrastructure.

Start Monitoring Free