CWE-359
195 CVEs • Abstraction: Base
Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
CVEs (195)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removin...Show more |
1Cross Fetch Project 1Cross Fetch Jun 17, 2026 Apr 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5. |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity docume...Show more |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The...Show more |
1Easyappointments 1Easy!appointments Jun 17, 2026 Mar 9, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. |
1Fluture Node Project 1Fluture Node Jun 17, 2026 Mar 1, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirectsWith` with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a...Show more |
2Follow Redirects Project Siemens2Follow Redirects Sinec InsJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor |
1Emuse Eservices / Envoice Project 1Emuse Eservices / Envoice Jun 17, 2026 Dec 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service. |
elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Sep 2, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could lev...Show more |
An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 11.1.11. A specially crafted series of network requests can lead to the disclosure of sensitive infor...Show more |
8Broadcom DebianFedoraproject+5 more12Communications Billing And Revenue Management Debian LinuxEssbase+9 moreJun 17, 2026 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials f...Show more |
On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between the Juniper device and...Show more |
3Nextcloud OpensuseSuse3Backports Sle Nextcloud ServerPackage HubJun 17, 2026 Feb 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup Server without any further data when the Lookup server is disabled. |
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode. |