← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Sep 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.
2Openstack
Redhat
2Barbican
Openstack Platform
Jun 17, 2026
Sep 24, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
1Easyregistrationforms
1Easy Registration Forms
Jun 17, 2026
Sep 23, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode in versions up to, and including, 2.1.1 due to insufficient controls on the information retrievable...Show more
The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode in versions up to, and including, 2.1.1 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabilities or above, to retrieve arbitrary sensitive user meta.Show less
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 21, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The appl...Show more
An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The application does not sufficiently restrict user-supplied paths, allowing for an authenticated attacker to read arbitrary files from a remote system, including the private key used to authenticate to agents for remote access.Show less
3Myprestamodules
Simpleimportproduct ProjectUpdateproducts Project
3Product Catalog (csv, Excel) Import
SimpleimportproductUpdateproducts
Jun 17, 2026
Sep 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
1Earthgarden Waiting Project
1Earthgarden Waiting
Jun 17, 2026
Sep 20, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Kokoroe Members Card Project
1Kokoroe Members Card
Jun 17, 2026
Sep 20, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send crafted messages.
1Ibm
1Robotic Process Automation
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. IBM X-Force ID: 261606.
1Ibm
1Storage Protect
Jun 17, 2026
Sep 20, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456.
1Schollz
1Croc
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.
1Ormazabal
2Ekorccp Firmware
Ekorrci Firmware
Jun 17, 2026
Sep 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenti...Show more
Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server.Show less
1Lovasoa
1Sqlpage
Jun 17, 2026
Sep 18, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration fi...Show more
SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable), with the web_root is the current working directory (the default), and with their database exposed publicly, is vulnerable to an attacker retrieving database connection information from SQLPage and using it to connect to their database directly. Version 0.11.0 fixes this issue. Some workarounds are available. Using an environment variable instead of the configuration file to specify the database connection string prevents exposing it on vulnerable versions. Using a different web root (that is not a parent of the SQLPage configuration directory) fixes the issue. One should also avoid exposing one's database publicly.Show less
1Tdsql Chitu Project
1Tdsql Chitu
Jun 17, 2026
Sep 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via get_db_info function in install.php.
1Strapi
1Strapi
Jun 17, 2026
Sep 15, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows...Show more
Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows a field they don't have permission to see, the field will still be visible. Version 4.12.1 has a fix for this issue.Show less
1Strapi
1Strapi
Jun 17, 2026
Sep 15, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/...Show more
Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/relations` route does not remove private fields or ensure that they can't be selected. This issue is fixed in version 4.11.7.Show less
1Fortinet
1Fortisiem
Jun 17, 2026
Sep 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request.
1Fortinet
1Forticlient Endpoint Management Server
Jun 17, 2026
Sep 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unau...Show more
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment variables such as the EMS installation path.Show less
1Te St
1Leyka
Jun 17, 2026
Sep 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subsc...Show more
The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7 via the 'leyka_ajax_get_env_and_options' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including Sberbank API key and password, PayPal Client Secret, and more keys and passwords.Show less
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
Sep 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft Outlook Information Disclosure Vulnerability
1Apache
1Airflow
Jun 17, 2026
Sep 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration...Show more
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to see the task/dag in the UI, to craft a URL, which could lead to unmasking the secret configuration of the task that otherwise would be masked in the UI. Users are strongly advised to upgrade to version 2.7.1 or later which has removed the vulnerability.Show less