Skip to main content

CWE archive

CWE-1230 CVEs

Programmatic archive

25 CVEs tagged with CWE-12300 Critical, 5 High, 17 Medium, 3 Low, 0 Unrated.

CVE-2026-45544

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-49270

Published Jun 1, 2026

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network conne…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-31959

Published May 6, 2026

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location infor…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-29055

Published Mar 26, 2026

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the image processing pipeline in Tandoor Recipes e…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27661

Published Mar 10, 2026

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as infor…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13084

Published Nov 26, 2025

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will d…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2025-30038

Published Aug 27, 2025

The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores…

CVSS 7.3 · High

CVE-2025-8713

Published Aug 14, 2025

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row s…

CVSS 3.1 · Low

CVE-2023-50458

Published Jul 10, 2025

In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-48941

Published Jun 2, 2025

MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existen…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0330

Published Mar 20, 2025

In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability expose…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9447

Published Mar 20, 2025

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, all…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9099

Published Mar 20, 2025

In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1921

Published Mar 5, 2025

Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (C…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-26527

Published Feb 24, 2025

Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10324

Published Jan 24, 2025

The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47517

Published Jan 10, 2025

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53291

Published Dec 25, 2024

Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potential…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8910

Published Sep 25, 2024

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render functio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6962

Published May 2, 2024

The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32488

Published Aug 16, 2023

Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1974

Published Apr 11, 2023

Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1