Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-497

MITRE ↗

CWE-497

14
CRITICAL
68
HIGH
249
MEDIUM
28
LOW
382 CVEs · Page 4/8
7.5
CVE-2025-31045

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Fo

7.5
CVE-2024-51770

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

7.5
CVE-2025-27721

Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthoriz

7.5
CVE-2025-43024

A GUI dialog of an application allows to view what files are in the file system without proper authorization.

7.5
CVE-2025-54459

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd witho

7.5
CVE-2025-14712

Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil

7.5
CVE-2025-34442

AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in

7.5
CVE-2025-64258

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post fo

6.8
CVE-2025-46421

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorizatio

6.7
CVE-2025-47319

Information disclosure while exposing internal TA-to-TA communication APIs to HLOS

6.5
CVE-2024-37526

IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authentica

6.5
CVE-2025-32164

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadLis

6.5
CVE-2025-52752

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeAtelier IDonatePro idon

6.5
CVE-2025-34283

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept

6.5
CVE-2024-13998

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (includ

6.5
CVE-2025-49914

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu

6.5
CVE-2025-64270

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le

6.5
CVE-2025-64272

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing

6.5
CVE-2025-67546

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret

6.5
CVE-2025-68551

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form

6.0
CVE-2025-0055

SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attack

6.0
CVE-2025-0056

SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or a

6.0
CVE-2025-0059

Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser st

5.9
CVE-2022-50237

The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair impleme

5.7
CVE-2025-46747

An authenticated user without user-management permissions could identify other user accounts.

5.5
CVE-2024-11029

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence

5.5
CVE-2025-23382

Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Infor

5.5
CVE-2025-2598

When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which

5.5
CVE-2025-30170

Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system inf

5.5
CVE-2025-49419

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for W

5.5
CVE-2025-54422

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.

5.5
CVE-2025-43406

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to a

5.5
CVE-2025-43471

The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sens

5.3
CVE-2024-52367

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthori

5.3
CVE-2024-45640

IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against

5.3
CVE-2024-40706

IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid

5.3
CVE-2025-26758

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social M

5.3
CVE-2024-10940

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized us

5.3
CVE-2025-31832

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector acf-c

5.3
CVE-2025-32251

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in J. Tyler Wiest Jetpack Feedb

5.3
CVE-2025-32255

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ERA404 StaffList stafflist a

5.3
CVE-2022-43852

IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in furthe

5.3
CVE-2025-39556

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control

5.3
CVE-2025-39439

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Markus Drubba wpLike2Get wpl

5.3
CVE-2025-47540

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail wemail allows

5.3
CVE-2025-3506

Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 an

5.3
CVE-2025-30011

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within th

5.3
CVE-2025-39394

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP al

5.3
CVE-2025-23969

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in whassan KI Live Video Confer

5.3
CVE-2025-49147

Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a

Frequently Asked Questions

What is CWE-497?

CWE-497 (CWE-497) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-497?

There are 382 CVE records associated with CWE-497 in our database. Of these, 14 are critical severity, 68 are high severity, and 249 are medium severity.

How can I protect against CWE-497 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-497 using AI-powered security agents.

Detect CWE-497 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-497 vulnerabilities across your infrastructure.

Get Started