Skip to main content

CWE archive

CWE-497 CVEs

Programmatic archive

367 CVEs tagged with CWE-49713 Critical, 62 High, 264 Medium, 28 Low, 0 Unrated.

CVE-2026-58246

Published Jul 28, 2026

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged use…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-66438

Published Jul 27, 2026

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65564

Published Jul 27, 2026

Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59548

Published Jul 27, 2026

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59528

Published Jul 27, 2026

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-59178

Published Jul 27, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44955

Published Jul 23, 2026

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discove…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-28698

Published Jul 23, 2026

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying h…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65535

Published Jul 23, 2026

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65521

Published Jul 23, 2026

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65505

Published Jul 23, 2026

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65498

Published Jul 23, 2026

Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65490

Published Jul 23, 2026

Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65474

Published Jul 23, 2026

Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65458

Published Jul 23, 2026

Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-61945

Published Jul 23, 2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2023-37507

Published Jul 21, 2026

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-10588

Published Jul 16, 2026

A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50294

Published Jul 14, 2026

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.

CVSS 6.2 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-61977

Published Jul 13, 2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affe…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-61976

Published Jul 13, 2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.T…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-61975

Published Jul 13, 2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue af…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57393

Published Jul 13, 2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embe…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-14808

Published Jul 6, 2026

Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obt…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-55726

Published Jul 3, 2026

The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9
Showing 1-25 of 367 CVEsPage 1 of 15