Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-598

MITRE ↗

CWE-598

4
CRITICAL
13
HIGH
12
MEDIUM
6
LOW
36 CVEs
9.8
CVE-2025-69270

Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux

9.8
CVE-2026-74880

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro

9.8
CVE-2026-76179

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication

9.0
CVE-2025-69634

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges

8.1
CVE-2026-23846

Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password au

8.1
CVE-2026-54652

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut

7.5
CVE-2025-41772

An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL

7.5
CVE-2026-25118

immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich applica

7.5
CVE-2026-34969

Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback f

7.5
CVE-2026-34020

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint us

7.5
CVE-2026-44883

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t

7.5
CVE-2026-58656

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Cont

7.5
CVE-2026-62386

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query

7.5
CVE-2026-15322

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the

7.5
CVE-2026-63408

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0

7.4
CVE-2026-14838

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc.

7.1
CVE-2026-26721

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensiti

6.8
CVE-2026-43875

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php comp

6.5
CVE-2026-66832

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app

6.2
CVE-2026-2237

A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager

5.9
CVE-2025-59873

An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s

5.9
CVE-2025-13219

IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information

5.5
CVE-2026-47768

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-

5.5
CVE-2026-82181

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote

5.3
CVE-2026-22644

Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft throu

5.3
CVE-2026-26196

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik

5.3
CVE-2026-31381

An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb

5.3
CVE-2026-37504

Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyControlle

4.3
CVE-2026-33620

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` throug

3.7
CVE-2026-16207

A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file

3.1
CVE-2025-14811

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o

3.1
CVE-2025-14808

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from

2.7
CVE-2026-10078

A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec

2.6
CVE-2025-62317

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive

2.0
CVE-2026-27949

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica

CVE-2026-9592

SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user sess

Frequently Asked Questions

What is CWE-598?

CWE-598 (CWE-598) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-598?

There are 36 CVE records associated with CWE-598 in our database. Of these, 4 are critical severity, 13 are high severity, and 12 are medium severity.

How can I protect against CWE-598 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-598 using AI-powered security agents.

Detect CWE-598 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-598 vulnerabilities across your infrastructure.

Get Started