The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
Volume of CVEs assigned to CWE-598 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-15322HIGH IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs. | Jul 17, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-62386HIGH The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBear | Jul 17, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-54652HIGH Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigat | Jul 8, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-9592HIGH SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclose | Jul 17, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-58656HIGH Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to m | Jul 8, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-23846CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query par | Jan 19, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-44883HIGH Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. Fro | May 28, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-69270CRITICAL Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spect | Jan 12, 2026 | 9.8 | 31 | NO | NO |
CVE-2017-3185CRITICAL ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensiti | Dec 16, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-14822CRITICAL Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate | Oct 2, 2018 | 9.8 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.