CWE-202Base

Exposure of Sensitive Information Through Data Queries

Draft in the CWE catalog · 34 CVEs mapped

34
CVEs mapped
7.3
Median CVSS
What it is

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

Recent examples
none
CVE-2026-16520

CVE-2026-16520 - UNKNOWN Severity Vulnerability

Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass. This issue affects Genian NAC V4.0: from 4.0.0 before 4.0.175(Revision 150340); Genian NAC V5.0: from 5.0.0 before 5.0.65 LTS(Revision 150331), from 5.0.0 before 5.0.75 LTS(Revision 150330), from 5.0.0 before 5.0.87 Release Stable(Revision 150329), and from 5.0.0 before 5.0.88(Revision 150328); Genian ZTNA V6.0: from 6.0.0 before 6.0.26 LTS(Revision 150337), from 6.0.0 before 6.0.35 LTS(Revision 150336), from 6.0.0 before 6.0.47 Release Stable(Revision 150334), and from 6.0.0 before 6.0.48(Revision 150333).

no explanation yet
0%
epss
7.3cvss
CVE-2026-25703

CVE-2026-25703 - HIGH Severity Vulnerability

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.

HIGHno explanation yet
0%
epss
none
CVE-2026-70473

CVE-2026-70473 - UNKNOWN Severity Vulnerability

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-202
Abstraction
Base
Structure
Simple
Status
Draft
References (2)