Skip to main content

CWE archive

CWE-359 CVEs

Programmatic archive

195 CVEs tagged with CWE-3592 Critical, 67 High, 101 Medium, 25 Low, 0 Unrated.

CVE-2026-50657

Published Jul 14, 2026

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.

CVSS 4.7 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-62328

Published Jul 13, 2026

9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to un…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-58297

Published Jul 3, 2026

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-58296

Published Jul 3, 2026

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-57960

Published Jun 29, 2026

Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and pe…

CVSS 8.3 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-56124

Published Jun 29, 2026

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database t…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-48615

Published Jun 26, 2026

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they ma…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54264

Published Jun 22, 2026

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an infor…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-49344

Published Jun 19, 2026

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/admin/queries/execute`) accepts…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-25762

Published Jun 19, 2026

Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projec…

CVSS 8.7 · High

CVE-2025-30459

Published Jun 11, 2026

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-26237

Published Jun 10, 2026

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthori…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25699

Published Jun 9, 2026

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked p…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2020-25900

Published Jun 5, 2026

HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a dat…

CVSS 5.3 · Medium

CVE-2026-8990

Published May 28, 2026

A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by inter…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-13477

Published May 21, 2026

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authent…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-28963

Published May 11, 2026

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intellig…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66172

Published May 8, 2026

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, wh…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66171

Published May 8, 2026

The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, wh…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-7382

Published Apr 30, 2026

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDK…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-41182

Published Apr 23, 2026

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-28950

Published Apr 22, 2026

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and iPadOS 18.7.8, iOS…

CVSS 6.2 · Medium
evidence mentions
16
Buzz score
48.3
Vendor/product tagsBeta · best-effort

CVE-2026-6765

Published Apr 21, 2026

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 195 CVEsPage 1 of 8