← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moxa
1Iologik E4200 Firmware
Jun 17, 2026
Aug 24, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulner...Show more
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the purpose of assessing vulnerabilities and potential attack vectors.Show less
1Lenovo
87Ideapad 1 14ijl7 Firmware
Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 more
Jun 17, 2026
Aug 23, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI.
1Lenovo
87Ideapad 1 14ijl7 Firmware
Ideapad 1 15ijl7 FirmwareIdeapad 1 14iau7 Firmware+84 more
Jun 17, 2026
Aug 23, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Control...Show more
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands.Show less
1Apache
1Airflow
Jun 17, 2026
Aug 23, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection...Show more
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by sending many requests, leading to a denial of service (DoS) condition on the server. Furthermore, malicious actors can leverage this vulnerability to establish harmful connections with the server. Users of Apache Airflow are strongly advised to upgrade to version 2.7.0 or newer to mitigate the risk associated with this vulnerability. Additionally, administrators are encouraged to review and adjust user permissions to restrict access to sensitive functionalities, reducing the attack surface.Show less
1Danfoss
1Ak Sm 800a Firmware
Jun 17, 2026
Aug 21, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.
1Microsoft
1Edge Chromium
Jun 17, 2026
Aug 21, 2023
N/A· v4
3.1 LOW· v3
N/A· v2
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
1Butterfly Button
1Butterfly Button
Jun 17, 2026
Aug 21, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) allows loss of plausible deniability and confidentiality.This issue aff...Show more
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) allows loss of plausible deniability and confidentiality.This issue affects BUTTERFLY BUTTON: As of 2023-08-21.Show less
1Acymailing
1Acymailing
Jun 17, 2026
Aug 17, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.
1Jenkins
1Gogs
Jun 17, 2026
Aug 16, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.
1Dell
1Powerscale Onefs
Jun 17, 2026
Aug 16, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation o...Show more
Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges. Show less
1Revmakx
1Infinitewp Client
Jun 17, 2026
Aug 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-...Show more
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.Show less
1Google
1Android
Jun 17, 2026
Aug 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional...Show more
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Show less
1Yaklang
1Yaklang
Jun 17, 2026
Aug 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file inclusion (LFI) vulnerability. This vulnerability allows attackers to include files from the server's lo...Show more
yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file inclusion (LFI) vulnerability. This vulnerability allows attackers to include files from the server's local file system through the web application. When exploited, this can lead to the unintended exposure of sensitive data, potential remote code execution, or other security breaches. Users utilizing versions of the Yak Engine prior to 1.2.4-sp1 are impacted. This vulnerability has been patched in version 1.2.4-sp1. Users are advised to upgrade. users unable to upgrade may avoid exposing vulnerable versions to untrusted input and to closely monitor any unexpected server behavior until they can upgrade.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Aug 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Aug 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.
1Intel
11Nuc 11 Performance Kit Nuc11pahi30z Firmware
Nuc 11 Performance Kit Nuc11pahi3 FirmwareNuc 11 Performance Kit Nuc11pahi50z Firmware+8 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor in BIOS firmware for some Intel(R) NUCs may allow a privilege user to potentially enable information disclosure via local access.
1Ivanti
1Avalanche
Jun 17, 2026
Aug 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader+1 more
Jun 17, 2026
Aug 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTL...Show more
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must open a maliciously crafted Microsoft Office file, or visit an attacker controlled web page.Show less
1Linuxfoundation
1Opentelemetry Instrumentation For Java
Jun 17, 2026
Aug 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumentation prior to version 1.28.0 contains an issue related to the instrumen...Show more
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumentation prior to version 1.28.0 contains an issue related to the instrumentation of Java applications using the AWS SDK v2 with Amazon Simple Email Service (SES) v1 API. When SES POST requests are instrumented, the query parameters of the request are inserted into the trace `url.path` field. This behavior leads to the http body, containing the email subject and message, to be present in the trace request url metadata. Any user using a version before 1.28.0 of OpenTelemetry Java Instrumentation to instrument AWS SDK v2 call to SES’s v1 SendEmail API is affected. The e-mail content sent to SES may end up in telemetry backend. This exposes the e-mail content to unintended audiences. The issue can be mitigated by updating OpenTelemetry Java Instrumentation to version 1.28.0 or later.Show less
1Microsoft
12Windows 10
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows Hyper-V Information Disclosure Vulnerability