Skip to main content

CWE archive

CWE-612 CVEs

Programmatic archive

11 CVEs tagged with CWE-6120 Critical, 3 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2019-25605

Published Mar 22, 2026

EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridg…

CVSS 8.7 · High

CVE-2025-3660

Published Jan 4, 2026

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploiti…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-3654

Published Jan 4, 2026

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to device hardware information by exploit…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-3653

Published Jan 4, 2026

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary seri…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-57756

Published Aug 28, 2025

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and b…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49071

Published Dec 12, 2024

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-25635

Published Feb 19, 2024

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using t…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4560

Published Aug 28, 2023

Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41918

Published Nov 15, 2022

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level secu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-35980

Published Aug 12, 2022

OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an inf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22565

Published Apr 12, 2022

Dell PowerScale OneFS, versions 9.0.0-9.3.0, contain an improper authorization of index containing sensitive information. An authenticated and privileged user could potentially ex…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1