CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory. |
1Atlassian 2Jira Data Center Jira ServerJun 17, 2026 Jun 18, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. This Information Disclosure vulnerability, with a CVSS Score of 7.4, allows an...Show more |
Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their o...Show more |
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API. |
Vulnerability of insufficient permission verification in the NearLink module
Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerabilit...Show more |
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.0 and prior to versions 1.13.7, 1.14.12, and 1.15.6, the output of `cilium-bugtool` can contain sensitiv...Show more |
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability leading to information...Show more |
1Adobe 1Framemaker Publishing Server Jun 17, 2026 Jun 13, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker could exploit this vulnerability...Show more |
1Microsoft 1Azure Data Science Virtual Machine Jul 20, 2026 Jun 11, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability |
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 20, 2026 Jun 11, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Cryptographic Services Information Disclosure Vulnerability |
1Beyondtrust 1Beyondinsight Password Safe Jun 17, 2026 Jun 11, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response. |
1Wpmet 1Metform Elementor Contact Form Builder Jun 17, 2026 Jun 11, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. T...Show more |
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or before |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jun 11, 2024 N/A· v4 6.0 MEDIUM· v3 N/A· v2 On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jun 11, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the applica...Show more |
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project administrators can run these imports, which could cause Allura to read from internal services and expos...Show more |
A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information about the agent on affected installations. Please note: an...Show more |
This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen. |