Total
164 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27850 | 1 Apple | 5 Ipados, Iphone Os, Macos and 2 more | 2025-11-04 | N/A | 6.5 MEDIUM |
|
This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5, iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to fingerprint the user.
|
|||||
| CVE-2025-43357 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2025-11-04 | N/A | 3.3 LOW |
|
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26 and iPadOS 26. An app may be able to fingerprint the user.
|
|||||
| CVE-2025-43310 | 1 Apple | 1 Macos | 2025-11-04 | N/A | 4.4 MEDIUM |
|
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Sequoia 15.7. An app may be able to trick a user into copying sensitive data to the pasteboard.
|
|||||
| CVE-2025-43301 | 1 Apple | 1 Macos | 2025-11-04 | N/A | 3.3 LOW |
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.8, macOS Sequoia 15.7. An app may be able to access contact info related to notifications in Notification Center.
|
|||||
| CVE-2023-45721 | 1 Hcltech | 1 Domino Leap | 2025-11-04 | N/A | 5.3 MEDIUM |
|
Insufficient default configuration in HCL Leap
allows anonymous access to directory information.
|
|||||
| CVE-2025-43259 | 1 Apple | 1 Macos | 2025-11-03 | N/A | 4.6 MEDIUM |
|
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensitive user information.
|
|||||
| CVE-2025-43217 | 1 Apple | 2 Ipados, Iphone Os | 2025-11-03 | N/A | 4.0 MEDIUM |
|
The issue was addressed by adding additional logic. This issue is fixed in iPadOS 17.7.9, iOS 18.6 and iPadOS 18.6. Privacy Indicators for microphone or camera access may not be correctly displayed.
|
|||||
| CVE-2025-31276 | 1 Apple | 2 Ipados, Iphone Os | 2025-11-03 | N/A | 5.3 MEDIUM |
|
This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.
|
|||||
| CVE-2024-42325 | 1 Zabbix | 1 Zabbix | 2025-11-03 | N/A | 3.5 LOW |
|
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
|
|||||
| CVE-2025-43279 | 1 Apple | 1 Macos | 2025-11-03 | N/A | 6.2 MEDIUM |
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.
|
|||||
| CVE-2025-62644 | 1 Rbi | 1 Restaurant Brands International Assistant | 2025-10-31 | N/A | 5.0 MEDIUM |
|
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.
|
|||||
| CVE-2025-35981 | 2025-10-27 | N/A | 5.5 MEDIUM | ||
|
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view.
This issue affects Command Centre Server: 9.30.1874 (MR1), 9.20.2337 (MR3), 9.10.3194 (MR6).
|
|||||
| CVE-2025-11145 | 2025-10-27 | N/A | 7.5 HIGH | ||
|
Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trade Inc. EnVision allows Account Footprinting.This issue affects enVision: before 250566.
|
|||||
| CVE-2025-53950 | 3 Apple, Fortinet, Microsoft | 3 Macos, Fortidlp Agent, Windows | 2025-10-16 | N/A | 5.5 MEDIUM |
|
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.
|
|||||
| CVE-2025-62362 | 2025-10-14 | N/A | N/A | ||
|
gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name and email address of employees who publish content are exposed in network responses and can be discovered by viewing the browser's developer tools network tab. This information disclosure may violate employee privacy expectations and could be used for targeted attacks or unwanted contact. This issue has been patched in versions 2.0.3, 3.0.2, and 4.0.1. No known workarounds exi ...
Show More |
|||||
| CVE-2025-5009 | 2025-10-08 | N/A | N/A | ||
|
In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable public link that contained the entire conversation history and not just the snippet.
|
|||||
| CVE-2025-10859 | 1 Mozilla | 1 Firefox | 2025-10-03 | N/A | 4.0 MEDIUM |
|
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143.1.
|
|||||
| CVE-2025-1939 | 1 Mozilla | 1 Firefox | 2025-09-29 | N/A | 3.9 LOW |
|
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.
|
|||||
| CVE-2025-53374 | 1 Dokploy | 1 Dokploy | 2025-09-29 | N/A | 4.3 MEDIUM |
|
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly invoking user.one. The response discloses personally-identifiable information (PII) such as e-mail address, role, two-factor status, organization ID, and various account flags. The fix will be available in the v0.23.7.
|
|||||
| CVE-2024-49765 | 1 Discourse | 1 Discourse | 2025-09-26 | N/A | 5.3 MEDIUM |
|
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse. Users unable to upgrade who are using discourse connect may disable all other login methods as a workaround.
|
|||||
| CVE-2024-28387 | 1 Axonaut | 1 Axonaut | 2025-09-18 | N/A | 7.5 HIGH |
|
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.
|
|||||
| CVE-2025-51586 | 1 Prestashop | 1 Prestashop | 2025-09-12 | N/A | 3.7 LOW |
|
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
|
|||||
| CVE-2024-11206 | 2025-09-05 | N/A | 7.5 HIGH | ||
|
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.
|
|||||
| CVE-2025-54124 | 1 Xwiki | 1 Xwiki | 2025-09-02 | N/A | 6.5 MEDIUM |
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with editing rights can create an XClass with a database list property that references a password property. When adding an object of that XClass, the content of that password property is displayed. In practice, with a standard right ...
Show More |
|||||
| CVE-2025-54125 | 1 Xwiki | 1 Xwiki | 2025-09-02 | N/A | 6.5 MEDIUM |
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1.0, the XML export of a page in XWiki that can be triggered by any user with view rights on a page by appending ?xpage=xml to the URL includes password and email properties stored on a document that aren't named password or email. This is fixed in ver ...
Show More |
|||||
| CVE-2025-6017 | 1 Redhat | 1 Advanced Cluster Management For Kubernetes | 2025-08-20 | N/A | 5.5 MEDIUM |
|
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
|
|||||
| CVE-2024-11216 | 2025-08-19 | N/A | 7.6 HIGH | ||
|
Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik Online allows Account Footprinting, Session Hijacking.This issue affects Pik Online: before 3.1.5.
|
|||||
| CVE-2025-41685 | 2025-08-19 | N/A | 6.5 MEDIUM | ||
|
A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.
|
|||||
| CVE-2025-53765 | 1 Microsoft | 2 Azure App Service On Azure Stack, Azure Stack Hub | 2025-08-18 | N/A | 4.4 MEDIUM |
|
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
|
|||||
| CVE-2024-10267 | 1 Superagi | 1 Superagi | 2025-07-18 | N/A | 7.5 HIGH |
|
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that is already in use. The server returns all information associated with the existing account. The vulnerable endpoint is located in the user registration functionality.
|
|||||
| CVE-2025-49715 | 1 Microsoft | 1 Dynamics 365 | 2025-07-17 | N/A | 7.5 HIGH |
|
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.
|
|||||
| CVE-2025-49134 | 1 Weblate | 1 Weblate | 2025-07-16 | N/A | 5.3 MEDIUM |
|
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.
|
|||||
| CVE-2025-53625 | 2025-07-15 | N/A | N/A | ||
|
The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames that have been hidden using revision deletion, suppression, or the hideuser block flag. The vulnerability is fixed in 3.6.4.
|
|||||
| CVE-2025-5334 | 1 Devolutions | 1 Remote Desktop Manager | 2025-07-02 | N/A | 7.5 HIGH |
|
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager
allows an authenticated user to gain unauthorized access to private personal information.
Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users.
This issue affects the following versions :
* Remote Desktop Manager Windows 2025.1.34.0 and ear ...
Show More |
|||||
| CVE-2023-36052 | 1 Microsoft | 1 Azure Command-line Interface | 2025-07-02 | N/A | 8.6 HIGH |
|
Azure CLI REST Command Information Disclosure Vulnerability
|
|||||
| CVE-2023-42830 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2025-06-16 | N/A | 3.3 LOW |
|
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.
|
|||||
| CVE-2021-22876 | 8 Broadcom, Debian, Fedoraproject and 5 more | 12 Fabric Operating System, Debian Linux, Fedora and 9 more | 2025-06-09 | 5.0 MEDIUM | 5.3 MEDIUM |
|
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.
|
|||||
| CVE-2024-11396 | 1 Awplife | 1 Event Monster | 2025-06-05 | N/A | 5.3 MEDIUM |
|
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.
|
|||||
| CVE-2025-0679 | 1 Gitlab | 1 Gitlab | 2025-05-29 | N/A | 4.3 MEDIUM |
|
An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.
|
|||||
| CVE-2024-13228 | 1 Themeum | 1 Qubely | 2025-05-26 | N/A | 4.3 MEDIUM |
|
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, password-protected, draft, and trashed post data.
|
|||||