← Back
CWE-359

195 CVEs • Abstraction: Base

Exposure of Private Personal Information to an Unauthorized Actor

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

JSON object

Loading...

CVEs (195)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Feb 28, 2025
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.
1Jegtheme
1Jeg Elementor Kit
Jun 17, 2026
Feb 27, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for aut...Show more
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.11 via the 'expired_data' and 'build_content' functions. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.Show less
1Qardio
1Qardio
Jun 17, 2026
Feb 13, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in t...Show more
The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal.Show less
1Wpwax
1Directorist
Jun 17, 2026
Feb 1, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/direct...Show more
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including including usernames, email addresses, names, and more information about users.Show less
-
-
Jun 17, 2026
Jan 31, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/...Show more
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.Show less
-
-
Jun 17, 2026
Jan 30, 2025
8.2 HIGH· v4
5.9 MEDIUM· v3
N/A· v2
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confid...Show more
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle scenario.Show less
-
-
Jun 17, 2026
Jan 24, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution...Show more
Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth credentials, the credentials are being leaked in the application execution logs in case of failure. Credentials are properly sanitized when the operation is successful but not when for whatever reason there is a failure in the maven repository, e.g. wrong coordinates provided, not existing artifact or version. Version 0.93.0 contains a patch for the issue.Show less
1Webtechstreet
1Elementor Addon Elements
Jun 17, 2026
Jan 15, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. Th...Show more
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.Show less
1Awplife
1Event Monster
Jun 17, 2026
Jan 14, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the e...Show more
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.3 via the Visitors List Export file. During the export, a CSV file is created in the wp-content folder with a hardcoded filename that is publicly accessible. This makes it possible for unauthenticated attackers to extract data about event visitors, that includes first and last names, email, and phone number.Show less
1Ibm
1Jazz Foundation
Jun 17, 2026
Jan 3, 2025
N/A· v4
4.6 MEDIUM· v3
N/A· v2
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.
1Discourse
1Discourse
Jun 17, 2026
Dec 19, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. Th...Show more
Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to bypass discourse connect to create accounts and login. This problem is patched in the latest version of Discourse. Users unable to upgrade who are using discourse connect may disable all other login methods as a workaround.Show less
1Wpjobportal
1Wp Job Portal
Jun 17, 2026
Dec 14, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() fu...Show more
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.Show less
1Ruijienetworks
1Reyee Os
Jun 17, 2026
Dec 6, 2024
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie'...Show more
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's servicesShow less
1Autolabproject
1Autolab
Jun 17, 2026
Nov 25, 2024
7.1 HIGH· v4
5.3 MEDIUM· v3
N/A· v2
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, usi...Show more
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for leakage of submissions to unauthorized users, such as downloading submissions from other students in the class, or even instructor test submissions, given they know their user IDs. This issue has been patched in commit `1aa4c769` which is not yet in a release version, but is expected to be included in version 3.0.3. Users are advised to either manually patch or to wait for version 3.0.3. As a workaround administrators can disable the feature.Show less
1Microsoft
1Edge Chromium
Jun 17, 2026
Nov 14, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
-
-
Jun 17, 2026
Nov 14, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.
1Fortinet
3Fortianalyzer
Fortianalyzer Big DataFortimanager
Jun 17, 2026
Nov 12, 2024
N/A· v4
4.1 MEDIUM· v3
N/A· v2
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with admini...Show more
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP or HTTPs requests.Show less
1Acronis
1Cyber Files
Jun 17, 2026
Oct 17, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
1Apexsoftcell
2Ld Dp Back Office
Ld Geo
Jun 17, 2026
Sep 19, 2024
8.7 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by m...Show more
This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.Show less
1Apexsoftcell
2Ld Dp Back Office
Ld Geo
Jun 17, 2026
Sep 19, 2024
8.7 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this...Show more
This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to exposure of sensitive information belonging to other users.Show less