Threats Tagged 'cwe-524'
View all threats tagged with 'cwe-524'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-524'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-25703: CWE-306 Missing authentication for critical function in SUSE NeuVectorCVE-2026-25703 0 NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information. Join the discussion | CVE Database V5 | 08/05/2026, 09:48:19 UTC Added: 08/05/2026, 10:12:00 UTC |
CVE-2026-65755: CWE-524 Use of Cache Containing Sensitive Information in regularlabs.com Articles Anywhere extension for JoomlaCVE-2026-65755 0 Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable. Join the discussion | CVE Database V5 | 07/23/2026, 09:14:11 UTC Added: 07/23/2026, 09:22:47 UTC |
CVE-2026-64648: CWE-524: Use of Cache Containing Sensitive Information in vercel next.jsCVE-2026-64648 0 Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11. Join the discussion | GCVE Database | 07/27/2026, 19:20:42 UTC Added: 07/23/2026, 01:18:05 UTC |
CVE-2026-64792: CWE-524 Use of Cache Containing Sensitive Information in regularlabs.com Articles Anywhere extension for JoomlaCVE-2026-64792 0 Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors. Join the discussion | CVE Database V5 | 07/22/2026, 20:40:58 UTC Added: 07/22/2026, 21:08:29 UTC |
Showing 1 to 4 of 4 results