Vulnerabilities (CVE)

Filtered by CWE-497
Total 401 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-47319 1 Qualcomm 236 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 233 more 2026-06-17 N/A 6.7 MEDIUM
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-46747 2026-06-17 N/A 5.7 MEDIUM
An authenticated user without user-management permissions could identify other user accounts.
CVE-2025-46718 1 Trifectatech 1 Sudo 2026-06-17 N/A 3.3 LOW
sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users' permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.
CVE-2025-46717 1 Trifectatech 1 Sudo 2026-06-17 N/A 3.3 LOW
sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges can determine whether files exists in folders that they otherwise cannot access using `sudo --list <pathname>`. Users with local access to a machine can discover the existence/non-existence of certain files, revealing potentially sensitive information in the file names. This information can also be used in conjunction with other attacks. Version 0.2.6 fixes the vulnerability.
CVE-2025-44823 1 Nagios 1 Log Server 2026-06-17 N/A 9.9 CRITICAL
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.
CVE-2025-43471 1 Apple 1 Macos 2026-06-17 N/A 5.5 MEDIUM
The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
CVE-2025-43406 1 Apple 1 Macos 2026-06-17 N/A 5.5 MEDIUM
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
CVE-2025-43024 1 Hp 1 Thinpro 2026-06-17 N/A 7.5 HIGH
A GUI dialog of an application allows to view what files are in the file system without proper authorization.
CVE-2025-41763 1 Mbs-solutions 4 Ubr-01 Mk Ii, Ubr-02, Ubr-lon and 1 more 2026-06-17 N/A 6.5 MEDIUM
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource available to administrators, including system backups and certificate request files.
CVE-2025-3606 2026-06-17 N/A 7.5 HIGH
Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing sensitive information, such as credentials which could be used to further compromise the device.
CVE-2025-3506 1 Checkmk 1 Checkmk 2026-06-17 N/A 5.3 MEDIUM
Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.
CVE-2025-39589 1 Wpdeveloper 1 Essential Addons For Elementor 2026-06-17 N/A 4.3 MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Retrieve Embedded Sensitive Data.This issue affects Essential Addons for Elementor: from n/a through <= 6.1.9.
CVE-2025-39556 2026-06-17 N/A 5.3 MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensitive Data.This issue affects Mediavine Control Panel: from n/a through <= 2.10.6.
CVE-2025-39439 2026-06-17 N/A 5.3 MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Markus Drubba wpLike2Get wplike2get allows Retrieve Embedded Sensitive Data.This issue affects wpLike2Get: from n/a through <= 1.2.9.
CVE-2025-39394 2026-06-17 N/A 5.3 MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP allows Retrieve Embedded Sensitive Data.This issue affects AnalyticsWP: from n/a through 2.1.2.
CVE-2025-36373 1 Ibm 1 Datapower Gateway 2026-06-17 N/A 4.1 MEDIUM
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user.
CVE-2025-36238 1 Ibm 1 Powervm Hypervisor 2026-06-17 N/A 6.0 MEDIUM
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.
CVE-2025-36229 1 Ibm 1 Aspera Faspex 2026-06-17 N/A 3.1 LOW
IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.
CVE-2025-36162 1 Ibm 1 Devops Deploy 2026-06-17 N/A 4.3 MEDIUM
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system.
CVE-2025-36160 1 Ibm 1 Concert 2026-06-17 N/A 5.3 MEDIUM
IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.