Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-359 (侵犯隐私) — Vulnerability Class 147

147 vulnerabilities classified as CWE-359 (侵犯隐私). AI Chinese analysis included.

CWE-359 represents a critical security weakness where software fails to restrict access to sensitive personal data, allowing unauthorized individuals or entities to view private information without explicit permission or implicit consent. Attackers typically exploit this vulnerability by bypassing authentication mechanisms, exploiting broken access controls, or leveraging insecure direct object references to retrieve data such as social security numbers, financial records, or health details. To mitigate this risk, developers must implement robust identity verification and strict role-based access controls that enforce the principle of least privilege. Additionally, employing comprehensive encryption for data at rest and in transit, alongside rigorous input validation and regular security audits, ensures that only authorized users can interact with sensitive information, thereby preserving user privacy and maintaining regulatory compliance.

MITRE CWE Description
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
Common Consequences (1)
Confidentiality Read Application Data
Mitigations (3)
Requirements Identify and consult all relevant regulations for personal privacy. An organization may be required to comply with certain federal and state regulations, depending on its location, the type of business it conducts, and the nature of any private data it handles. Regulations may include Safe Harbor Privacy Framework [REF-340], Gramm-Leach Bliley Act (GLBA) [REF-341], Health Insurance Portability a…
Architecture and Design Carefully evaluate how secure design may interfere with privacy, and vice versa. Security and privacy concerns often seem to compete with each other. From a security perspective, all important operations should be recorded so that any anomalous activity can later be identified. However, when private data is involved, this practice can in fact create risk. Although there are many ways in which pri…
Implementation, Operation Some tools can automatically analyze documents to redact, strip, or "sanitize" private information, although some human review might be necessary. Tools may vary in terms of which document formats can be processed. When calling an external program to automatically generate or convert documents, invoke the program with any available options that avoid generating sensitive metada…
Examples (2)
The following code contains a logging statement that tracks the contents of records added to a database by storing them in a log file. Among other values that are stored, the getPassword() function returns the user-supplied plaintext password associated with the account.
pass = GetPassword(); ... dbmsLog.WriteLine(id + ":" + pass + ":" + type + ":" + tstamp);
Bad · C#
This code uses location to determine the user's current US State location.
<uses-permission android:name="android.permission.ACCESS_FINE_LOCATION"/>
Bad · XML
locationClient = new LocationClient(this, this, this); locationClient.connect(); Location userCurrLocation; userCurrLocation = locationClient.getLastLocation(); deriveStateFromCoords(userCurrLocation);
Bad · Java
CVE ID Title CVSS Severity Published
CVE-2026-102579 Moodle: user profile information disclosure via grade web service 4.3 Medium 2026-09-30
CVE-2026-39372 InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments — InvoicePlane 4.9 Medium 2026-09-25
CVE-2026-92565 Rallly before 4.15.0 Information Disclosure via polls.get — rallly 5.3 Medium 2026-09-16
CVE-2026-76855 Netcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit Endpoints — NR255-V 6.5 Medium 2026-09-15
CVE-2026-88875 AVideo Incomplete API Sanitization Information Disclosure — AVideo 4.3 Medium 2026-09-10
CVE-2026-73008 Windows Biometric Service Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium 2026-09-08
CVE-2026-69351 Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium 2026-09-08
CVE-2026-21827 HCL Connections is vulnerable to an information disclosure vulnerability — Connections 3.1 Low 2026-08-31
CVE-2026-48048 XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests — xwiki-platform 7.5 High 2026-08-10
CVE-2026-24078 Exposure of Private Personal Information to an Unauthorized Actor in Data Modem — Snapdragon 6.5 Medium 2026-08-04
CVE-2026-56171 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability — Remote Desktop Web Client 7.1 High 2026-07-17
CVE-2026-50657 Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability — Microsoft Defender for Endpoint for Mac 4.7 Medium 2026-07-14
CVE-2026-58297 Microsoft Edge for Android Information Disclosure Vulnerability — Microsoft Edge (Chromium-based) 7.1 High 2026-07-03
CVE-2026-58296 Microsoft Edge for Android Information Disclosure Vulnerability — Microsoft Edge (Chromium-based) 7.1 High 2026-07-03
CVE-2026-57960 Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id — Hi.Events 6.5 Medium 2026-06-29
CVE-2026-56124 phpUploader < 2.0.2 Unauthenticated Database Exposure via index model — phpUploader 7.5 High 2026-06-29
CVE-2026-48615 nodejs node.js 信息泄露漏洞 — node - - 2026-06-26
CVE-2026-49344 Mercator has a Personal Identifiable Information Leak from Query Executor feature — mercator - - 2026-06-19
CVE-2019-25762 Joomla! Component JoomProject 1.1.3.2 Information Disclosure — JoomProject 7.5 High 2026-06-19
CVE-2026-25699 Apache Answer: Authorization Bypass in Timeline API — Apache Answer - - 2026-06-09
CVE-2020-25900 HelloTalk 安全漏洞 — HelloTalk 5.3 Medium 2026-06-05
CVE-2025-13477 OTP Bypass in Digital Operation Services' WifiBurada — WifiBurada 7.1 High 2026-05-21
CVE-2025-66172 Apache CloudStack: Any user can attach a volume in their VMs from backups they should not have access to — Apache CloudStack 6.5AI Medium AI 2026-05-08
CVE-2025-66171 Apache CloudStack: Any user can create a new VM from backups they should not have access to — Apache CloudStack 6.5AI Medium AI 2026-05-08
CVE-2025-15623 Sparx Pro Cloud Server reveals sensitive information to an unauthenticated user — Sparx Pro Cloud Server 7.5AI High AI 2026-04-17
CVE-2026-3911 Org.keycloak.services.resources.admin.userresource: keycloak: information disclosure of disabled user attributes via administrative endpoint — Red Hat build of Keycloak 26.4 2.7 Low 2026-03-11
CVE-2026-0102 Microsoft Edge (Chromium-based) Defense in Depth Vulnerability — Microsoft Edge (Chromium-based) 3.1 Low 2026-02-17
CVE-2020-37173 AVideo Platform 8.1 - Information Disclosure (User Enumeration) — AVideo Platform 7.5 High 2026-02-11
CVE-2026-24321 Information Disclosure vulnerability in SAP Commerce Cloud — SAP Commerce Cloud 5.3 Medium 2026-02-10
CVE-2025-66605 Yokogawa FAST/TOOLS 安全漏洞 — FAST/TOOLS 6.1AI Medium AI 2026-02-09

Vulnerabilities classified as CWE-359 (侵犯隐私) represent 147 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.