← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.
1Atlassian
2Jira Data Center
Jira Server
Jun 17, 2026
Jun 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an...Show more
This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability which has high impact to confidentiality, no impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Jira Core Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8 Jira Core Data Center 9.16: Upgrade to a release greater than or equal to 9.16.0 See the release notes. You can download the latest version of Jira Core Data Center from the download center. This vulnerability was found internally.Show less
1Lobehub
1Lobe Chat
Jun 17, 2026
Jun 17, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their o...Show more
Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side request. This issue has been addressed in version 0.162.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Guoxinled
1Synthesis Image System
Jun 17, 2026
Jun 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jun 14, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
1Nvidia
2Cloud Gaming
Virtual Gpu
Jun 17, 2026
Jun 13, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerabilit...Show more
NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.Show less
1Cilium
1Cilium
Jun 17, 2026
Jun 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitiv...Show more
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitive data when the tool is run (with the `--envoy-dump` flag set) against Cilium deployments with the Envoy proxy enabled. Users of the TLS inspection, Ingress with TLS termination, Gateway API with TLS termination, and Kafka network policies with API key filtering features are affected. The sensitive data includes the CA certificate, certificate chain, and private key used by Cilium HTTP Network Policies, and when using Ingress/Gateway API and the API keys used in Kafka-related network policy. `cilium-bugtool` is a debugging tool that is typically invoked manually and does not run during the normal operation of a Cilium cluster. This issue has been patched in Cilium v1.15.6, v1.14.12, and v1.13.17. There is no workaround to this issue.Show less
1Microsoft
1Telemetry Dashboard
Jun 17, 2026
Jun 13, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability leading to information...Show more
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability leading to information disclosure.Show less
1Adobe
1Framemaker Publishing Server
Jun 17, 2026
Jun 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability...Show more
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability to gain access to sensitive information which may include system or user privileges. Exploitation of this issue does not require user interaction.Show less
1Microsoft
1Azure Data Science Virtual Machine
Jul 20, 2026
Jun 11, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
1Microsoft
1Dynamics 365
Jul 20, 2026
Jun 11, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
1Microsoft
9Windows 10 1809
Windows 10 21h2Windows 10 22h2+6 more
Jul 20, 2026
Jun 11, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Cryptographic Services Information Disclosure Vulnerability
1Beyondtrust
1Beyondinsight Password Safe
Jun 17, 2026
Jun 11, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
1Wpmet
1Metform Elementor Contact Form Builder
Jun 17, 2026
Jun 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. T...Show more
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users.Show less
1Netiq
1Access Manager
Jun 17, 2026
Jun 11, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Jun 11, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker...Show more
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Jun 11, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the applica...Show more
SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.Show less
1Apache
1Allura
Jun 17, 2026
Jun 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expos...Show more
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL.  Project administrators can run these imports, which could cause Allura to read from internal services and expose them. This issue affects Apache Allura from 1.0.1 through 1.16.0. Users are recommended to upgrade to version 1.17.0, which fixes the issue. If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file. Show less
1Trendmicro
1Apex One
Jun 17, 2026
Jun 10, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations. Please note: an...Show more
A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Apple
1Watchos
Jun 17, 2026
Jun 10, 2024
N/A· v4
2.4 LOW· v3
N/A· v2
This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen.