← Back
CWE-200

10,415 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,415)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Contest Gallery
1Contest Gallery
Jun 17, 2026
Aug 26, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.
1Purevpn
1Purevpn
Jun 17, 2026
Aug 25, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers.
1Cyberark
1Identity
Jun 17, 2026
Aug 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Cyberark
1Identity
Jun 17, 2026
Aug 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Cyberark
1Identity
Jun 17, 2026
Aug 25, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Maxfoundry
1Maxbuttons
Jun 17, 2026
Aug 24, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path...Show more
The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 9.7.8. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.Show less
1Mage
1Mage Ai
Jun 17, 2026
Aug 22, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
-
-
Jun 17, 2026
Aug 21, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration informa...Show more
An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration information in a manner that could be compromised. With the default settings when installed for all users, the object can be accessible and (via its fields) could disclose some keys. These disclosed components can be combined to create a valid session via the Docusign API. This will generally lead to a complete compromise of the Docusign account because the session is for an administrator service account and may have permission to re-authenticate as specific users with the same authorization flow.Show less
-
-
Jun 17, 2026
Aug 21, 2024
5.1 MEDIUM· v4
N/A· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allows Retrieve Embedded Sensitive Data.This issue affects Performance Center: 12.63.
-
-
Jun 17, 2026
Aug 21, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.0. This is due the plugin utilizing mobiledetect without preventin...Show more
The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.1.0. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.Show less
-
-
Jun 17, 2026
Aug 21, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled...Show more
The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site.Show less
1Keyfactor
1Aws Orchestrator
Jun 17, 2026
Aug 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
1Barix
1Sip Client Firmware
Jun 17, 2026
Aug 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
1Priority Software
1Priority
Jun 17, 2026
Aug 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Zzcms
1Zzcms
Jun 17, 2026
Aug 19, 2024
5.3 MEDIUM· v4
7.5 HIGH· v3
4.0 MEDIUM· v2
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPH...Show more
A vulnerability was found in ZZCMS 2023. It has been rated as problematic. This issue affects some unknown processing of the file 3/E_bak5.1/upload/eginfo.php. The manipulation of the argument phome with the input ShowPHPInfo leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Nepstech
1Ntpl Xpon1gfevn Firmware
Jun 17, 2026
Aug 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter
1Nepstech
1Ntpl Xpon1gfevn Firmware
Jun 17, 2026
Aug 19, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of encryption during login process
1Cilium
1Cilium
Jun 17, 2026
Aug 16, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly...Show more
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x branch prior to 1.15.8 and the 1.16.x branch prior to 1.16.1, ReferenceGrant changes are not correctly propagated in Cilium's GatewayAPI controller, which could lead to Gateway resources being able to access secrets for longer than intended, or to Routes having the ability to forward traffic to backends in other namespaces for longer than intended. This issue has been patched in Cilium v1.15.8 and v1.16.1. As a workaround, any modification of a related Gateway/HTTPRoute/GRPCRoute/TCPRoute CRD (for example, adding any label to any of these resources) will trigger a reconciliation of ReferenceGrants on an affected cluster.Show less
1Relevanssi
1Relevanssi
Jun 17, 2026
Aug 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limit...Show more
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.Show less
1Tamparongj03
1Online Graduate Tracer System
Jun 17, 2026
Aug 15, 2024
6.9 MEDIUM· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The manipulation leads to inf...Show more
A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less