Threats Tagged 'cwe-359'
View all threats tagged with 'cwe-359'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-359'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-54565 is a vulnerability in the rhwp HWP viewer and editor and its Chrome and Firefox extensions prior to versions 0.7.15 and 0.2.4 respectively. The browser extensions use all-URLs host permissions but do not validate message senders or URL schemes before privileged fetches. This allows an untrusted page to request localhost or private network resources and potentially read preview images embedded in HWP or HWPX files as data URIs accessible to page scripts. The flaw also enables internal resource existence and port probing and extension fingerprinting. Exploitation requires user interaction by visiting a malicious page while the extension is enabled. The issue is fixed in rhwp 0.7.15 and the Chrome and Firefox extensions 0.2.4. Join the discussion | CVE Database V5 | 09/17/2026, 20:19:10 UTC Added: 09/17/2026, 20:47:39 UTC |
0 djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sending fields such as `password` (the hash), privilege flags (e.g. `is_staff` / `is_superuser`), tokens, and other PII to the browser. Because exposing model objects to templates is a normal djust pattern, this could leak credentials/PII without the developer realizing the full object crossed the wire. This is fixed in djust 1.0.7. Model serialization applies a secure-by-default sensitive-field denylist (password/hash/token/secret-style fields and known privilege flags are withheld) with an identity-subset fallback. As a workaround, keep `Model` instances on `_private` attributes and expose only the specific fields needed, until patched. Join the discussion | CVE Database V5 | 09/16/2026, 22:04:03 UTC Added: 09/16/2026, 22:32:16 UTC |
0 Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:01 UTC Added: 09/08/2026, 17:26:40 UTC |
0 Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:15:10 UTC Added: 09/08/2026, 17:24:57 UTC |
0 HCL Connections versions 7.0 and 8.0 contain an information disclosure vulnerability (CWE-359) that allows unauthorized users to access sensitive information due to improper handling of request data. The vulnerability has a low severity with a CVSS score of 3.1. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time. Join the discussion | GCVE Database | 08/31/2026, 15:48:17 UTC Added: 08/31/2026, 17:50:49 UTC |
0 CrossWatch versions prior to 0.9.21 have an information exposure vulnerability where an unauthenticated GET request to /api/app-auth/status returns metadata about all active sessions. This includes IP addresses, User-Agent strings, internal session IDs, and session timestamps. The issue is fixed in version 0.9.21. Join the discussion | CVE Database V5 | 08/21/2026, 21:19:04 UTC Added: 08/21/2026, 21:37:54 UTC |
Gitea contains a vulnerability in its API path for changing repository visibility from public to private. When this change is made via the REST API, stale watch records are not cleared, allowing users who lost access to still see metadata of the now-private repository in their subscription list. This leads to exposure of repository metadata and inflated watcher counts. The issue affects versions from v1.25.4 up to but not including v1.27.0. The severity is medium with limited confidentiality impact and no integrity or availability impact. Join the discussion | GCVE Database | 08/13/2026, 16:44:58 UTC Added: 07/22/2026, 00:11:14 UTC |
0 XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be retrieved of a user. The check for password (and email properties) has been adjusted in XWiki 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17. As a workaround, the patch can be applied manually to the wiki page `XWiki.LiveTableResultsMacros`. Join the discussion | CVE Database V5 | 08/10/2026, 15:52:02 UTC Added: 08/10/2026, 16:11:46 UTC |
0 CVE-2026-24078 is an information disclosure vulnerability in Qualcomm Snapdragon products that occurs when IPSec negotiation fails or is not properly established during NG-eCall SIP signaling. This flaw can expose private personal information to unauthorized actors. The vulnerability has a CVSS 3.1 base score of 6.5, indicating a medium severity level. No official patch or remediation guidance has been provided by the vendor as of the publication date. The affected products include a broad range of Qualcomm Snapdragon chipsets and related components. Join the discussion | CVE Database V5 | 08/04/2026, 15:07:15 UTC Added: 08/04/2026, 15:42:02 UTC |
0 Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 07/17/2026, 21:34:17 UTC Added: 07/18/2026, 08:58:00 UTC |
Showing 1 to 10 of 67 results