← Back
CWE-200

10,399 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,399)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Xcode
Jun 17, 2026
Mar 31, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
Mar 31, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.
1Apple
1Macos
Jun 17, 2026
Mar 31, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
1Apple
1Macos
Jun 17, 2026
Mar 31, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.
1Apple
1Macos
Jun 17, 2026
Mar 31, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.2, watchOS 11.2. An attacker in a privi...Show more
The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.2, watchOS 11.2. An attacker in a privileged network position may be able to track a user's activity.Show less
1Zitadel
1Zitadel
Jun 17, 2026
Mar 31, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZIT...Show more
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the password prompt even if the user doesn't exist and report "Username or Password invalid". While the setting was correctly respected during the login flow, the user's username was normalized leading to a disclosure of the user's existence. This vulnerability is fixed in 2.71.6, 2.70.8, 2.69.9, 2.68.9, 2.67.13, 2.66.16, 2.65.7, 2.64.6, and 2.63.9.Show less
1Vitejs
1Vite
Jun 17, 2026
Mar 31, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server...Show more
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.Show less
-
-
Jun 17, 2026
Mar 29, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it pos...Show more
The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed file.Show less
1Arteche
1Satech Bcu Firmware
Jun 17, 2026
Mar 28, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials that users have within the web (.xml file). In order to exploit this vulnerability, the attacker must...Show more
SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials that users have within the web (.xml file). In order to exploit this vulnerability, the attacker must know the path, regardless of the user's privileges on the website.Show less
1Fortinet
5Fortiddos
Fortiddos CmFortimail+2 more
Jun 17, 2026
Mar 28, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, versi...Show more
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, version 4.6.0, version 4.5.0, version 4.4.2 and below, FortiDDoS-CM version 5.3.0, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0, FortiVoice version 6.0.6 and below, FortiRecorder version 6.0.3 and below and FortiMail version 6.4.1 and below, version 6.2.4 and below, version 6.0.9 and below may allow a remote, unauthenticated attacker to obtain potentially sensitive software-version information by reading a JavaScript file.Show less
-
-
Jun 17, 2026
Mar 28, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it po...Show more
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.Show less
1Libming
1Libming
Jun 17, 2026
Mar 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
1Libming
1Libming
Jun 17, 2026
Mar 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
1Libming
1Libming
Jun 17, 2026
Mar 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
1Libming
1Libming
Jun 17, 2026
Mar 27, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
1Splunk
2Splunk
Splunk Cloud Platform
Jun 17, 2026
Mar 26, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208 and 9.1.2308.212, a low-privileged user that does not hold the “...Show more
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2406.108, 9.2.2403.113, 9.1.2312.208 and 9.1.2308.212, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on the “/app/search/search“ endpoint through its “s“ parameter. <br>The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.Show less
1Splunk
2Splunk
Splunk Cloud Platform
Jun 17, 2026
Mar 26, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Sp...Show more
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on the "/services/streams/search" endpoint through its "q" parameter. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.Show less
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Mar 26, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.
1Telesquare
1Tlr 2005ksh Firmware
Jun 17, 2026
Mar 26, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.
1Monospace
1Directus
Jun 17, 2026
Mar 26, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response bo...Show more
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response body encounters a ValidationError thrown by a failed condition operation, the API response includes sensitive data. This includes environmental variables, sensitive API keys, user accountability information, and operational data. This issue poses a significant security risk, as any unintended exposure of this data could lead to potential misuse. Version 11.5.0 fixes the issue.Show less