Skip to main content

CWE archive

CWE-525 CVEs

Programmatic archive

30 CVEs tagged with CWE-5250 Critical, 2 High, 21 Medium, 7 Low, 0 Unrated.

CVE-2024-23571

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41918

Published Jun 2, 2026

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when a…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-41322

Published Apr 24, 2026

@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match hea…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-15554

Published Mar 16, 2026

Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local ad…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36364

Published Mar 3, 2026

IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27514

Published Feb 23, 2026

Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuratio…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24437

Published Jan 26, 2026

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, br…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-52659

Published Jan 19, 2026

HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthoriz…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-13083

Published Nov 18, 2025

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52625

Published Oct 10, 2025

A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifiers, or internal file paths to att…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-36082

Published Sep 15, 2025

IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48947

Published Jun 4, 2025

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth…

CVSS 7.7 · High

CVE-2025-1334

Published Jun 3, 2025

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another u…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27525

Published May 15, 2025

Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager:…

CVSS 3.9 · Low

CVE-2024-45314

Published Sep 4, 2024

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. T…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-30130

Published Jul 19, 2024

HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-25142

Published Jun 14, 2024

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of so…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43841

Published May 30, 2024

IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2