n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensi
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information S
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect
Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers
SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent
Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Applicati
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unau
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and
D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve se
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers t
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Tel
A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lea
IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be
A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema re
An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with net
Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.
Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF I
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Pro
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized atta
Frequently Asked Questions
What is CWE-497?
CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-497?
There are 129 CVE records associated with CWE-497 in our database. Of these, 3 are critical severity, 31 are high severity, and 83 are medium severity.
How can I protect against CWE-497 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.
Detect CWE-497 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.
Get Started