Auto-created placeholder
Volume of CVEs assigned to CWE-199 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5405CRITICAL 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterp | Jun 8, 2017 | 9.8 | 33 | NO | NO |
CVE-2025-58304MEDIUM Permission control vulnerability in the file management module.
Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Nov 28, 2025 | 5.5 | 19 | NO | NO |
CVE-2016-5486MEDIUM Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality via vectors | Oct 25, 2016 | 5.5 | 19 | NO | NO |
CVE-2014-1591MEDIUM Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that rece | Dec 11, 2014 | 4.3 | 18 | NO | NO |
CVE-2024-51522MEDIUM Vulnerability of improper device information processing in the device management module
Impact: Successful exploitation of this vulnerability may affect availability. | Nov 5, 2024 | 5.5 | 17 | NO | NO |
CVE-2016-10841MEDIUM The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). | Aug 1, 2019 | 5.3 | 17 | NO | NO |
CVE-2015-8346MEDIUM app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issue | Apr 12, 2016 | 5.3 | 16 | NO | NO |
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-bas | Dec 11, 2014 | 2.1 | 15 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.