Threats Tagged 'cwe-497'
View all threats tagged with 'cwe-497'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-497'
Click on any threat for detailed analysis and mitigation recommendations
0 GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs. Join the discussion | CVE Database V5 | 09/24/2026, 07:07:49 UTC Added: 09/24/2026, 07:33:13 UTC |
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. Join the discussion | CVE Database V5 | 09/23/2026, 18:14:47 UTC Added: 09/23/2026, 18:19:49 UTC |
0 IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment. Join the discussion | CVE Database V5 | 09/18/2026, 15:39:51 UTC Added: 09/18/2026, 15:47:09 UTC |
0 A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes. Join the discussion | CVE Database V5 | 09/16/2026, 07:49:48 UTC Added: 09/16/2026, 08:02:20 UTC |
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware. Join the discussion | CVE Database V5 | 09/11/2026, 14:44:37 UTC Added: 09/11/2026, 15:02:33 UTC |
0 CVE-2026-61911 is a medium severity vulnerability in Cyrus IMAP before version 3.12.4. It allows an authenticated user to use a Sieve script to determine the existence of another user's private mailbox or read shared mailbox annotations by observing LMTP delivery behavior. This exposure of sensitive system information could aid in further reconnaissance but does not allow modification or denial of service. Join the discussion | CVE Database V5 | 09/09/2026, 00:00:00 UTC Added: 09/09/2026, 20:08:09 UTC |
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:19:02 UTC Added: 09/08/2026, 17:27:11 UTC |
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:54 UTC Added: 09/08/2026, 17:27:09 UTC |
Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:15:05 UTC Added: 09/08/2026, 17:24:52 UTC |
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:14:43 UTC Added: 09/08/2026, 17:24:36 UTC |
Showing 1 to 10 of 164 results