CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1System Center Operations Manager Jun 17, 2026 Nov 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Open Management Infrastructure Information Disclosure Vulnerability |
Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filt...Show more |
1Maiwei Safety Production Control Platform Project 1Maiwei Safety Production Control Platform Jun 17, 2026 Nov 13, 2023 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in Maiwei Safety Production Control Platform 4.1. This issue affects some unknown processing of the file /TC/V2.7/ha.html of the component Intelligent...Show more |
1Maiwei Safety Production Control Platform Project 1Maiwei Safety Production Control Platform Jun 17, 2026 Nov 13, 2023 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability classified as problematic was found in Maiwei Safety Production Control Platform 4.1. This vulnerability affects unknown code of the file /api/DataDictionary/GetItemList. The manipulation leads to informa...Show more |
Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specific DAGs only, to read information about task instances in other DAGs. This is a different issue than...Show more |
1Phpgurukul 1Restaurant Table Booking System Jun 17, 2026 Nov 10, 2023 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file booking-details.php of the component Reservati...Show more |
1Telit 10Bgs5 Firmware Ehs5 FirmwareEhs6 Firmware+7 moreJun 17, 2026 Nov 10, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that...Show more |
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, there is an edge case where a bookmark remin...Show more |
The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.
|
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 H5P metadata automatically populated the author with the user's username, which could be sensitive information. |
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. A...Show more |
1Telit 10Bgs5 Firmware Ehs5 FirmwareEhs6 Firmware+7 moreJun 17, 2026 Nov 9, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that...Show more |
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster. |
The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality. |
Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality. |
Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. |
1Redhat 2Jboss Enterprise Application Platform Wildfly CoreJun 17, 2026 Nov 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access...Show more |
Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. |
1Arm 4Bifrost Gpu Kernel Driver Mali Gpu Kernel DriverMidgard Gpu Kernel Driver+1 moreJun 17, 2026 Nov 7, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.
|