Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-497

MITRE ↗

CWE-497

3
CRITICAL
31
HIGH
83
MEDIUM
2
LOW
129 CVEs · Page 1/3
9.9
CVE-2026-27494

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user

9.8
CVE-2026-14808

Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe

9.1
CVE-2026-44945

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An

8.7
CVE-2026-0240

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensi

8.6
CVE-2026-34413

Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector

8.6
CVE-2026-24222

NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co

8.6
CVE-2026-42047

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche

8.6
CVE-2026-28698

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr

8.2
CVE-2025-9986

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information S

8.1
CVE-2025-13691

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be

7.5
CVE-2025-9110

An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect

7.5
CVE-2020-36922

Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers

7.5
CVE-2020-36926

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent

7.5
CVE-2025-13651

Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Applicati

7.5
CVE-2025-15623

Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unau

7.5
CVE-2026-43654

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and

7.5
CVE-2018-25358

D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve se

7.5
CVE-2026-34891

Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.

7.5
CVE-2026-49056

Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <

7.5
CVE-2026-49066

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

7.5
CVE-2026-49068

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

7.5
CVE-2026-52694

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

7.5
CVE-2026-54824

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

7.5
CVE-2026-56060

Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.

7.5
CVE-2026-56124

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers t

7.5
CVE-2023-37507

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon

7.5
CVE-2026-59528

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

7.5
CVE-2026-59548

Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.

7.5
CVE-2026-66462

Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.

7.5
CVE-2024-58375

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into

7.5
CVE-2026-32468

Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.

7.5
CVE-2026-78268

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Tel

7.1
CVE-2025-55131

A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using

7.1
CVE-2025-47378

Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.

6.5
CVE-2025-67954

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking

6.5
CVE-2025-68046

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lea

6.5
CVE-2025-14150

IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM

6.5
CVE-2025-13616

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be

6.5
CVE-2025-41763

A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl

6.5
CVE-2026-25344

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema re

6.5
CVE-2026-0239

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with net

6.5
CVE-2026-40796

Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.

6.5
CVE-2026-42660

Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.

6.5
CVE-2026-48878

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.

6.5
CVE-2026-57316

Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

6.5
CVE-2026-57393

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF I

6.5
CVE-2026-61945

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Pro

6.5
CVE-2026-6373

Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow

6.5
CVE-2026-66444

Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.

6.2
CVE-2026-50294

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized atta

Frequently Asked Questions

What is CWE-497?

CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-497?

There are 129 CVE records associated with CWE-497 in our database. Of these, 3 are critical severity, 31 are high severity, and 83 are medium severity.

How can I protect against CWE-497 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.

Detect CWE-497 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.

Get Started