The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
Volume of CVEs assigned to CWE-525 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52659HIGH HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorize | Jan 19, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-41918MEDIUM A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an | Jun 2, 2026 | 5.7 | 26 | NO | NO |
CVE-2025-15554HIGH Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local adm | Mar 16, 2026 | 7.8 | 24 | NO | NO |
CVE-2025-52625HIGH A vulnerability
Cacheable SSL Page Found vulnerability has been identified
in HCL AION.
Cached data may expose credentials, system identifiers, or internal file paths to atta | Oct 10, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-23571MEDIUM HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be | Jul 17, 2026 | 4.3 | 22 | NO | NO |
CVE-2026-27514MEDIUM Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration | Feb 23, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-48947HIGH The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0 | Jun 4, 2025 | 7.7 | 22 | NO | NO |
CVE-2025-36364MEDIUM IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system. | Mar 3, 2026 | 6.2 | 21 | NO | NO |
CVE-2024-30130HIGH HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information. | Jul 19, 2024 | 7.5 | 21 | NO | NO |
CVE-2026-41322MEDIUM @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match head | Apr 24, 2026 | 5.3 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.