CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
379 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-34413 — Xerte Online Toolkits Missing Authentication via connector.php
- CVE-2025-10264 — Digiever|NVR - Exposure of Sensitive Information
- CVE-2025-47699 — Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration
- CVE-2025-44823 — Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi
- CVE-2025-6561 — Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information
- CVE-2025-5893 — Honding Technology Smart Parking Management System - Exposure of Sensitive Information
- CVE-2025-1144 — Quanxun School Affairs System - Exposure of Sensitive Information
- CVE-2024-4008 — FDSK Leak in KNX Secure Devices
- CVE-2025-11545 — Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions proj
- CVE-2025-12779 — Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,
- CVE-2024-39675 — A vulnerability has been identified in RUGGEDCOM RMC30 (All versions < V4.3.10), RUGGEDCOM RMC30NC (All versions < V4.3.
- CVE-2025-9364 — Rockwell Automation FactoryTalk® Analytics™ LogixAI® Exposed Redis DB
- CVE-2025-59098 — Trace Functionality Leaking Sensitive Data in dormakaba access manager
- CVE-2025-54459 — Vertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CVE-2025-4364 — Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CVE-2025-3606 — Vestel AC Charger Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CVE-2025-32792 — ses's global contour bindings leak into Compartment lexical scope
- CVE-2025-27721 — INFINITT Healthcare INFINITT PACS Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CVE-2025-14712 — JHENG GAO|Student Learning Assessment and Support System - Exposure of Sensitive Information
- CVE-2025-0061 — Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform
Recently published
- CVE-2026-16006 — Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user t
- CVE-2026-76968 — Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
- CVE-2026-80119 — PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTL
- CVE-2026-80118 — PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL
- CVE-2026-66840 — XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sens
- CVE-2026-81774 — WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
- CVE-2026-78268 — WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure vulnerability
- CVE-2026-75928 — Brushfire unauthenticated information disclosure
- CVE-2026-67267 — Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthoriz
- CVE-2026-74007 — WordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure vulnerability
- CVE-2026-32468 — WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability
- CVE-2024-58375 — OpenTofu before 1.8.3 Secret Variable Leaking via Static Evaluation
- CVE-2026-66462 — WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure vulnerability
- CVE-2026-66444 — WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerability
- CVE-2025-15680 — Information Disclosure via UART
- CVE-2026-6373 — Sensitive Data Exposure in Zyxel WAH7601 Router
- CVE-2026-69127 — Kirby: System path exposure from error messages in the REST API
- CVE-2026-17595 — Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass
- CVE-2026-28169 — WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data Exposure vulnerability
- CVE-2026-44945 — Cross-Cluster Impersonation Confused-Deputy Privilege Escalation