CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed fo...Show more |
1Zoom 3Rooms Virtual Desktop InfrastructureZoomJun 17, 2026 Mar 16, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the...Show more |
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission. |
1Ibm 3Robotic Process Automation Robotic Process Automation As A ServiceRobotic Process Automation For Cloud PakJun 17, 2026 Mar 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032. |
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. IBM X-...Show more |
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695. |
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4.10.3 versions. |
Microsoft OneDrive for Android Information Disclosure Vulnerability |
Microsoft OneDrive for Android Information Disclosure Vulnerability |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, allows an attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not acc...Show more |
An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without a...Show more |
1Devolutions 1Remote Desktop Manager Jun 17, 2026 Mar 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell Module 2022.3.1.5 and earlier allows an authenticated user to access sensitive data...Show more |
1Qualcomm 183Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+180 moreJun 17, 2026 Mar 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information Disclosure in Graphics during GPU context switch. |
1Getadmiral 1Ad Blocking Detector Nov 21, 2024 Mar 10, 2023 N/A· v4 7.5 HIGH· v3 4.0 MEDIUM· v2 A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the file ad-blocking-detector.php. The manipulation leads t...Show more |
2Dronecode Yuneec2Mantis Q Firmware Px4 Drone AutopilotJun 17, 2026 Mar 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via various nuttx commands. |
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME e...Show more |
1Niteothemes 1Coming Soon & Maintenance Jun 17, 2026 Mar 7, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to...Show more |
Directus is a real-time API and App dashboard for managing SQL database content. In versions prior to 9.16.0 users with read access to the `password` field in `directus_users` can extract the argon2 password hashes by br...Show more |
libmemcached-awesome is an open source C/C++ client library and tools for the memcached server. `libmemcached` could return data for a previously requested key, if that previous request timed out due to a low `POLL_TIMEO...Show more |
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 through 7.2.1, 7.0.0 through 7.0.4 and 6.4.0 through 6.4.10 may allow a remote authenticated attacker...Show more |