Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-497

MITRE ↗

CWE-497

14
CRITICAL
68
HIGH
249
MEDIUM
28
LOW
382 CVEs · Page 3/8
4.3
CVE-2026-24377

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-p

4.3
CVE-2026-24553

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dotstore Fraud Prevention Fo

4.3
CVE-2026-24314

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which

4.3
CVE-2026-20691

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iP

4.3
CVE-2026-39469

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagela

4.3
CVE-2026-39566

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress

4.3
CVE-2026-39572

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Bo

4.3
CVE-2026-41339

OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin auth

4.3
CVE-2026-27349

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint all

4.3
CVE-2026-44749

The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request art

4.3
CVE-2026-24618

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements all

4.3
CVE-2026-57664

Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.

4.3
CVE-2026-65458

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P

4.3
CVE-2026-65535

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

4.3
CVE-2026-58246

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn

4.1
CVE-2025-36373

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I

4.0
CVE-2026-56569

HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config

3.7
CVE-2026-44743

Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l

3.5
CVE-2025-27550

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about o

CVE-2026-22537

The lack of hardening of the system allows the user used to manage and maintain the charger to consult different files c

CVE-2025-59098

The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality

CVE-2025-66599

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Physical paths could be displ

CVE-2026-0231

An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta

CVE-2026-7864

SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endp

CVE-2026-9307

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's 

CVE-2025-59178

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera

CVE-2026-17595

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select

CVE-2026-69127

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handl

CVE-2025-15680

TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph

10.0
CVE-2025-10264

Certain models of NVR developed by Digiever has an Exposure of Sensitive Information vulnerability, allowing unauthentic

9.9
CVE-2025-44823

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi

9.9
CVE-2025-47699

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration

9.8
CVE-2024-36554

Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36

9.8
CVE-2025-1144

School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view

9.8
CVE-2025-5893

Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing

9.8
CVE-2025-6561

Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne

9.8
CVE-2024-13999

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP

8.8
CVE-2025-9364

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redi

8.8
CVE-2024-13995

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account inform

8.8
CVE-2025-12779

Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,

8.7
CVE-2025-0061

SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over

8.6
CVE-2024-12367

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste

8.2
CVE-2025-11151

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized

7.7
CVE-2025-22222

VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privil

7.7
CVE-2024-45549

Information disclosure while creating MQ channels.

7.6
CVE-2025-30686

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: EMC). Sup

7.5
CVE-2024-8550

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4

7.5
CVE-2025-27934

Information disclosure of authentication information in the specific service vulnerability exists in Wi-Fi AP UNIT 'AC-W

7.5
CVE-2025-26730

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator wi

7.5
CVE-2025-3606

Vestel AC Charger version 3.75.0 contains a vulnerability that could enable an attacker to access files containing s

Frequently Asked Questions

What is CWE-497?

CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-497?

There are 382 CVE records associated with CWE-497 in our database. Of these, 14 are critical severity, 68 are high severity, and 249 are medium severity.

How can I protect against CWE-497 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.

Detect CWE-497 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.

Get Started