CWE-200
10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,330)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Austin Contract Computing 1Merchant Order Form Apr 16, 2026 Apr 1, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information. |
1Microsoft 3Backoffice Windows 2000Windows NtApr 16, 2026 Feb 12, 1999 N/A· v4 N/A· v3 2.1 LOW· v2 The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. |
1Microsoft 1Internet Information Server Apr 16, 2026 Jan 27, 1999 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. |
The RPC portmapper service is running. |
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). |
Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predict...Show more |
11Apple CiscoHp+8 more14Aix BsdosHp Ux+11 moreMay 28, 2026 Aug 1, 1997 N/A· v4 4.0 MEDIUM· v3 2.1 LOW· v2 ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. |
IRIX fam service allows an attacker to obtain a list of all files on the server. |
An SNMP community name is the default (e.g. public), null, or missing. |
1Microsoft 2Windows 2000 Windows NtMay 28, 2026 Jan 1, 1997 N/A· v4 9.1 CRITICAL· v3 7.5 HIGH· v2 IP forwarding is enabled on a machine which is not a router or firewall. |