← Back
CWE-200

10,368 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,368)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 5, 2026
Aug 14, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on rooted or debug-enabled devices. This presents a risk of user data exp...Show more
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data exfiltration via ADB backup on rooted or debug-enabled devices. This presents a risk of user data exposure.Show less
-
-
Jun 17, 2026
Aug 14, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.
-
-
Jun 17, 2026
Aug 14, 2025
8.5 HIGH· v4
N/A· v3
N/A· v2
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the conn...Show more
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.Show less
1Apache
1Superset
Jun 17, 2026
Aug 14, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database s...Show more
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user. This issue affects Apache Superset: before 4.1.3. Users are recommended to upgrade to version 4.1.3, which fixes the issue.Show less
-
-
Jun 17, 2026
Aug 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitive configuration data, including admin credentials.
-
-
Jun 17, 2026
Aug 13, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interface without authentication.
-
-
Jun 17, 2026
Aug 12, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the debug pack generated by Autocaliweb can expose sensitive configu...Show more
Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the debug pack generated by Autocaliweb can expose sensitive configuration data, including API keys. This occurs because the to_dict() method, used to serialize configuration for the debug pack, doesn't adequately filter out sensitive fields such as API tokens. Users, unaware of the full contents, might share these debug packs, inadvertently leaking their private API keys. This issue has been patched in version 0.8.3.Show less
1Microsoft
11Dcadsv5 Series Azure Vm Firmware
Dcasv5 Series Azure Vm FirmwareDcedsv5 Series Azure Vm Firmware+8 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network.
1Microsoft
1Dynamics 365
Jun 17, 2026
Aug 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
1Microsoft
3Windows 11 24h2
Windows Server 2022 23h2Windows Server 2025
Jun 17, 2026
Aug 12, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally.
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
1Microsoft
2Exchange Server
Exchange Server Subscription Edition
Jun 17, 2026
Aug 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
-
-
Jun 17, 2026
Aug 12, 2025
2.1 LOW· v4
2.6 LOW· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of s...Show more
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.Show less
1Checkpoint
1Harmony Sase
Jun 17, 2026
Aug 12, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
1Siemens
1Sinec Traffic Analyzer
Jun 17, 2026
Aug 12, 2025
7.0 HIGH· v4
7.8 HIGH· v3
N/A· v2
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes an internal service port to be accessible from outside the system. This could all...Show more
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes an internal service port to be accessible from outside the system. This could allow an unauthorized attacker to access the application.Show less
-
-
Jun 17, 2026
Aug 12, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenti...Show more
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.Show less
-
-
Jun 17, 2026
Aug 11, 2025
5.1 MEDIUM· v4
N/A· v3
N/A· v2
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, in...Show more
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.Show less
15kcrm
2Wukong Crm
Wukongcrm
Jul 14, 2026
Aug 11, 2025
2.1 LOW· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through...Show more
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less