CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program. |
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. |
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality. |
Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality. |
The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality. |
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations. |
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity. |
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. |
1Qualcomm 65Fastconnect 6700 Firmware Fastconnect 6800 FirmwareFastconnect 6900 Firmware+62 moreJun 17, 2026 Jul 4, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure in DSP Services while loading dynamic module. |
1Kingstemple 1The King's Temple Church Website Jun 17, 2026 Jul 3, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintenti...Show more |
1Zoom 9Meetings Poly Ccx 600 FirmwarePoly Ccx 700 Firmware+6 moreJun 17, 2026 Jun 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares...Show more |
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additi...Show more |
IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another tenant's account. IBM X-Force ID: 254136. |
1Apereo 1Central Authentication Service Jun 17, 2026 Jun 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Jun 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2
IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403.
|
Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). W...Show more |
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for una...Show more |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewa...Show more |
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extens...Show more |