Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-1230

Exposure of Sensitive Information Through Metadata

The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.

25
Assigned CVEs
303rd
Commonality Rank
5.7
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-1230 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2023
3 years ago
Most Recent CVE
Jun 1, 2026
52 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-49270MEDIUM
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connec
Jun 1, 20265.930NONO
CVE-2025-59601MEDIUM
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
Jun 1, 20266.527NONO
CVE-2025-13084HIGH
The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an Editor role to access and will di
Nov 26, 20257.625NONO
CVE-2025-47324HIGH
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
Aug 6, 20257.525NONO
CVE-2025-30038HIGH
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores a
Aug 27, 20257.323NONO
CVE-2026-45544MEDIUM
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in N
Jun 1, 20264.322NONO
CVE-2025-0330HIGH
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes
Mar 20, 20257.522NONO
CVE-2024-9099HIGH
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or
Mar 20, 20258.122NONO
CVE-2024-53291HIGH
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentiall
Dec 25, 20247.522NONO
CVE-2023-1974MEDIUM
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
Apr 11, 20236.521NONO
View all 25 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
8%
3.0-3.9
24%
10%
4.0-4.9
24%
19%
5.0-5.9
20%
16%
6.0-6.9
20%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products