The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
Volume of CVEs assigned to CWE-402 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23264CRITICAL Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes. | Dec 2, 2021 | 9.1 | 30 | NO | NO |
CVE-2022-3596HIGH An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the underc | Sep 20, 2023 | 7.5 | 25 | NO | NO |
CVE-2021-23263HIGH Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary). | Dec 2, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-67745HIGH MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1.3.0, in some cases, myhoard logs the whole backup info, inc | Dec 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-0502CRITICAL Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resou | Jan 15, 2025 | 9.1 | 24 | NO | NO |
CVE-2025-48383HIGH Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget can | May 27, 2025 | 8.2 | 23 | NO | NO |
CVE-2025-29925MEDIUM XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages e | Mar 19, 2025 | 5.3 | 23 | NO | YES |
CVE-2021-31410HIGH Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request | Apr 23, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-31407HIGH Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9), and 6.0.0 through 6.0.1 (Vaadin 19.0.0) allows attacker to | Apr 23, 2021 | 7.5 | 22 | NO | NO |
CVE-2017-8442MEDIUM Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration information, such as the paths and p | Jul 7, 2017 | 6.5 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.