Vulnerabilities (CVE)

Filtered by CWE-359
Total 157 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-43409 1 Apple 1 Macos 2025-12-17 N/A 5.5 MEDIUM
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.
CVE-2025-43399 1 Apple 1 Macos 2025-12-17 N/A 7.5 HIGH
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access protected user data.
CVE-2025-66510 1 Nextcloud 1 Nextcloud Server 2025-12-10 N/A 4.5 MEDIUM
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.
CVE-2025-66027 1 Rallly 1 Rallly 2025-12-03 N/A 6.5 MEDIUM
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy features are enabled. This bypasses intended privacy controls that should prevent participants from viewing other users’ personal information. This issue has been patched in version 4.5.6.
CVE-2025-36131 1 Ibm 1 Db2 2025-11-19 N/A 4.6 MEDIUM
IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) clpplus command exposes user credentials to the terminal which could be obtained by a third party with physical access to the system.
CVE-2023-45720 1 Hcltech 1 Hcl Leap 2025-11-17 N/A 5.3 MEDIUM
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
CVE-2024-7697 1 Transsion 1 Carlcare 2025-11-13 N/A 7.5 HIGH
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
CVE-2025-43452 1 Apple 2 Ipados, Iphone Os 2025-11-05 N/A 4.6 MEDIUM
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggestions may display sensitive information on the lock screen.
CVE-2023-45721 1 Hcltech 1 Domino Leap 2025-11-04 N/A 5.3 MEDIUM
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
CVE-2025-43259 1 Apple 1 Macos 2025-11-03 N/A 4.6 MEDIUM
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensitive user information.
CVE-2025-31276 1 Apple 2 Ipados, Iphone Os 2025-11-03 N/A 5.3 MEDIUM
This issue was addressed through improved state management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.
CVE-2024-42325 1 Zabbix 1 Zabbix 2025-11-03 N/A 3.5 LOW
Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc.
CVE-2025-43279 1 Apple 1 Macos 2025-11-03 N/A 6.2 MEDIUM
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.
CVE-2025-62644 1 Rbi 1 Restaurant Brands International Assistant 2025-10-31 N/A 5.0 MEDIUM
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.
CVE-2025-53950 3 Apple, Fortinet, Microsoft 3 Macos, Fortidlp Agent, Windows 2025-10-16 N/A 5.5 MEDIUM
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1 may allow an authenticated administrator to collect current user's email information.
CVE-2025-53374 1 Dokploy 1 Dokploy 2025-09-29 N/A 4.3 MEDIUM
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly invoking user.one. The response discloses personally-identifiable information (PII) such as e-mail address, role, two-factor status, organization ID, and various account flags. The fix will be available in the v0.23.7.
CVE-2024-49765 1 Discourse 1 Discourse 2025-09-26 N/A 5.3 MEDIUM
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse. Users unable to upgrade who are using discourse connect may disable all other login methods as a workaround.
CVE-2024-28387 1 Axonaut 1 Axonaut 2025-09-18 N/A 7.5 HIGH
An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.
CVE-2025-51586 1 Prestashop 1 Prestashop 2025-09-12 N/A 3.7 LOW
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
CVE-2025-54124 1 Xwiki 1 Xwiki 2025-09-02 N/A 6.5 MEDIUM
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with editing rights can create an XClass with a database list property that references a password property. When adding an object of that XClass, the content of that password property is displayed. In practice, with a standard rights setup, this means that any user with an account on the wiki can access password hashes of all users, and possibly other password properties (with hashed or plain storage) that are on pages that the user can view. This issue is fixed in versions 16.4.7, 16.10.5 and 17.2.0-rc-1.