← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hitachienergy
1Esoms
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details. The w...Show more
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, disclosing information about the underlying technology and other sensitive information details. The website unintentionally reveals sensitive information including technical details like version Info, endpoints, backend server, Internal IP. etc., which can potentially expose additional attack surface containing other interesting vulnerabilities. Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and...Show more
The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications. Show less
2Fedoraproject
Matrix
2Fedora
Synapse
Jun 17, 2026
Oct 31, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeser...Show more
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Oct 29, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. This vulnerability is due to an incomplet...Show more
IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. This vulnerability is due to an incomplete fix for CVE-2022-34352. IBM X-Force ID: 266808.Show less
1Lenovo
1App Store App
Jun 17, 2026
Oct 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to gain unauthorized access to sensitive user data used by other unrelated applications.
1Ocomon Project
1Ocomon
Jun 17, 2026
Oct 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to obtain sensitive information such as e-mails and usernames.
1Elastic
1Elastic Cloud On Kubernetes
Jun 17, 2026
Oct 26, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.
1Linecorp
1Line
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
1Linecorp
1Line
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
1Linecorp
1Line
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
1Linecorp
1Line
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
1Apple
4Ipados
Iphone OsTvos+1 more
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS 17.1 and iPadOS 17.1. A device may be passively tracked by its Wi-Fi MAC address...Show more
This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, tvOS 17.1, iOS 17.1 and iPadOS 17.1. A device may be passively tracked by its Wi-Fi MAC address.Show less
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to ac...Show more
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 17.1 and iPadOS 17.1. An attacker with physical access may be able to use Siri to access sensitive user data.Show less
1Networktocode
1Nautobot
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N...Show more
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose hashed user passwords as stored in the database to any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. This vulnerability has been patched in version 2.0.3. Show less
1Ethyca
1Fides
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows user...Show more
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows users to retrieve its configuration using the `GET api/v1/config` endpoint. The configuration data is filtered to suppress most sensitive configuration information before it is returned to the user, but even the filtered data contains information about the internals and the backend infrastructure, such as various settings, servers’ addresses and ports and database username. This information is useful for administrative users as well as attackers, thus it should not be revealed to low-privileged users. This vulnerability allows Admin UI users with roles lower than the owner role e.g. the viewer role to retrieve the config information using the API. The vulnerability has been patched in Fides version `2.22.1`. Show less
1Busbaer
1Eisbaer Scada
Jun 17, 2026
Oct 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Linecorp
1Regina Sweets&bakery
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
1Linecorp
1Matsuya
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
1Linecorp
1Fukunaga Memberscard
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
1Linecorp
1Uomasa Saiji New
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.