The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.
Volume of CVEs assigned to CWE-612 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3653CRITICAL Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary seria | Jan 4, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-3654CRITICAL Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to device hardware information by exploiti | Jan 4, 2026 | 9.8 | 30 | NO | NO |
CVE-2025-3660HIGH Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' pet data by exploitin | Jan 4, 2026 | 8.2 | 26 | NO | NO |
CVE-2022-35980HIGH OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an info | Aug 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2019-25605HIGH EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge | Mar 22, 2026 | 7.5 | 24 | NO | NO |
CVE-2024-25635HIGH alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization owners using th | Feb 19, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-49071MEDIUM Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a n | Dec 12, 2024 | 6.5 | 22 | NO | NO |
CVE-2022-41918MEDIUM OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level secur | Nov 15, 2022 | 6.3 | 22 | NO | NO |
CVE-2025-57756MEDIUM Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and be | Aug 28, 2025 | 5.3 | 20 | NO | NO |
CVE-2023-4560MEDIUM Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4. | Aug 28, 2023 | 6.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.