By weakness (CWE)
CWE-1230: related vulnerabilities
CVEs classified under CWE-1230. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
3 published vulnerabilities
- CVE-2025-59601MEDIUM 6.5
CVE-2025-59601 describes an information disclosure vulnerability in multiple Qualcomm wireless and audio components. When a device is factory reset through its powerline interface, sensitive configuration data may be exposed to an attacker with adjacent network access. This allows unauthorized parties to read device settings that should have been wiped during the reset process. The vulnerability does not allow modification of settings or denial of service, but the exposure of configuration details could enable further attacks or reveal sensitive operational parameters.
- CVE-2026-49270MEDIUM 5.9
Apache ActiveMQ brokers with network connectors configured to sync durable subscriptions are leaking sensitive metadata to unauthenticated attackers. An attacker can request a complete list of durable topic subscriptions, including client IDs, subscription names, destination topics, and JMS selector expressions—all without needing to authenticate. This occurs because the broker responds to BrokerInfo commands before validating the connection's authentication status.
- CVE-2026-45544MEDIUM 4.3
Nextcloud Tables, a collaborative document and data management component, contains an information disclosure vulnerability affecting versions 0.8.0 through 1.0.3. The issue allows users with read-only access to view filter criteria—potentially including sensitive column names, field definitions, or search logic—that should have been restricted to higher-privilege users. This represents a low-severity data exposure that could leak operational details about table structure and content filtering strategies. The vulnerability has been resolved in Nextcloud Tables versions 1.0.4 and 2.0.0.