← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerability will affect confidentiality.
1Huawei
1Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 5, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
1Qualcomm
65Fastconnect 6700 Firmware
Fastconnect 6800 FirmwareFastconnect 6900 Firmware+62 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Information disclosure in DSP Services while loading dynamic module.
1Kingstemple
1The King's Temple Church Website
Jun 17, 2026
Jul 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintenti...Show more
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase. If an unauthorized party gains access to this key, they could potentially carry out transactions on behalf of the organization, leading to financial losses. Additionally, they could access sensitive customer information, leading to privacy violations and potential legal implications. The affected component is the codebase of our project, specifically the file(s) where the Stripe API key is embedded. The key should have been stored securely, and not committed to the codebase. The maintainers plan to revoke the leaked Stripe API key immediately, generate a new one, and not commit the key to the codebase.Show less
1Zoom
9Meetings
Poly Ccx 600 FirmwarePoly Ccx 700 Firmware+6 more
Jun 17, 2026
Jun 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
1Nixos
1Calamares Nixos Extensions
Jun 17, 2026
Jun 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares...Show more
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of calamares-nixos-extensions version 0.3.12 and prior who installed NixOS through the graphical calamares installer, with an unencrypted `/boot`, on either non-UEFI systems or with a LUKS partition different from `/` have their LUKS key file in `/boot` as a plaintext CPIO archive attached to their NixOS initrd. A patch is available and anticipated to be part of version 0.3.13 to backport to NixOS 22.11, 23.05, and unstable channels. Expert users who have a copy of their data may, as a workaround, re-encrypt the LUKS partition(s) themselves.Show less
1Google
1Android
Jun 17, 2026
Jun 28, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additi...Show more
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912Show less
1Ibm
1Cloud Pak For Security
Jun 17, 2026
Jun 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to access data from another tenant's account. IBM X-Force ID: 254136.
1Apereo
1Central Authentication Service
Jun 17, 2026
Jun 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or...Show more
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authentication based on client X509 certificates. These certificates can be provided via TLS handshake or a special HTTP header, such as “ssl_client_cert”. When checking the validity of the provided client certificate, X509CredentialsAuthenticationHandler performs check that this certificate is not revoked. To do so, it fetches URLs provided in the “CRL Distribution Points” extension of the certificate, which are taken from the certificate itself and therefore can be controlled by a malicious user. If the CAS server is configured to use an LDAP server for x509 authentication with a password, for example by setting a “cas.authn.x509.ldap.ldap-url” and “cas.authn.x509.ldap.bind-credential” properties, X509CredentialsAuthenticationHandler fetches revocation URLs from the certificate, which can be LDAP urls. When making requests to this LDAP urls, Apereo CAS uses the same password as for initially configured LDAP server, which can lead to a password leak. An unauthenticated user can leak the password used to LDAP connection configured on server. This issue has been addressed in version 6.6.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jun 27, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403.
1Shopware
1Shopware
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). W...Show more
Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configuration file of the Javascript could be read in production environments (`themes/package-lock.json`). With this information, the specific Shopware version in a deployment might be determined by an attacker, which could be used for further attacks. Users are advised to update to version 5.7.18. There are no known workarounds for this vulnerability. Show less
1Mainwp
1Mainwp Child
Jun 17, 2026
Jun 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for una...Show more
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.4.1.1 due to insufficient controls on the storage of back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including the entire installations database if a backup occurs and the deletion of the back-up files fail.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Jun 23, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewa...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewable to the current user are leaked by the tags API. This information can also be exploited to infer the document reference of non-viewable pages. This vulnerability has been patched in XWiki 14.4.8, 14.10.4, and 15.0-rc-1. Show less
1Globalscape
1Eft Server
Jun 17, 2026
Jun 22, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extens...Show more
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message Show less