← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Allura
Jun 17, 2026
Nov 7, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them.  Exposing in...Show more
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them.  Exposing internal files then can lead to other exploits, like session hijacking, or remote code execution. This issue affects Apache Allura from 1.0.1 through 1.15.0. Users are recommended to upgrade to version 1.16.0, which fixes the issue.  If you are unable to upgrade, set "disable_entry_points.allura.importers = forge-tracker, forge-discussion" in your .ini config file. Show less
1Veeam
1One
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL serve...Show more
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.Show less
1Clastix
2Capsule
Capsule Proxy
Jun 17, 2026
Nov 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the right to list Namespaces of other tenants...Show more
capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same owner kind and name. For example consider two tenants `solar` and `wind`. Tenant `solar`, owned by a ServiceAccount named `tenant-owner` in the Namespace `solar`. Tenant `wind`, owned by a ServiceAccount named `tenant-owner` in the Namespace `wind`. The Tenant owner `solar` would be able to list the namespaces of the Tenant `wind` and vice-versa, although this is not correct. The bug introduces an exfiltration vulnerability since allows the listing of Namespace resources of other Tenants, although just in some specific conditions: 1. `capsule-proxy` runs with the `--disable-caching=false` (default value: `false`) and 2. Tenant owners are ServiceAccount, with the same resource name, but in different Namespaces. This vulnerability doesn't allow any privilege escalation on the outer tenant Namespace-scoped resources, since the Kubernetes RBAC is enforcing this. This issue has been addressed in version 0.4.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Nov 6, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 
1Ortussolutions
1Coldbox Elixir
Jun 17, 2026
Nov 6, 2023
N/A· v4
7.5 HIGH· v3
2.7 LOW· v2
A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation lead...Show more
A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrading to version 3.1.7 is able to address this issue. The identifier of the patch is a3aa62daea2e44c76d08d1eac63768cd928cd69e. It is recommended to upgrade the affected component. The identifier VDB-244485 was assigned to this vulnerability.Show less
1Ibm
1Robotic Process Automation For Cloud Pak
Jun 17, 2026
Nov 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exp...Show more
A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752.Show less
1Nokia
1G 040w Q Firmware
Jun 17, 2026
Nov 3, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially...Show more
Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.Show less
1Bestpractical
1Request Tracker
Jun 17, 2026
Nov 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
1Bestpractical
1Request Tracker
Jun 17, 2026
Nov 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.
1Bestpractical
1Request Tracker
Jun 17, 2026
Nov 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
1Kyocera
1D Copia253mf Plus Firmware
Jun 17, 2026
Nov 3, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a "nicht einloggen" error rather than a falsch error.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in shouzu sweets oz v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Lycorp
1Line Mini App
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Mattermost
1Mattermost Desktop
Jun 17, 2026
Nov 2, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.