CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Maximo Application Suite Maximo Asset ManagementJun 17, 2026 Feb 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further...Show more |
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privilege management when a specially crafted table access is used. IBM X-Force ID: 241671. |
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham i...Show more |
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure. |
1Sunellsecurity 7Sn Adr3804e1 Firmware Sn Adr3808e1 FirmwareSn Adr3808e2 Firmware+4 moreJun 17, 2026 Feb 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request. |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Feb 14, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high im...Show more |
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to ins...Show more |
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161, Acronis Cyber Protect 15 (Windows) before build 30984. |
In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. |
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. |
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. |
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. |
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. |
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. |
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page. |
1Dell 157Alienware 13 R2 Firmware Alienware 13 R3 FirmwareAlienware 15 R2 Firmware+154 moreJun 17, 2026 Feb 10, 2023 N/A· v4 4.2 MEDIUM· v3 N/A· v2 Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the system and knowledge of the system configuration could potentially exploit this vulnerability to re...Show more |
WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information. |
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log. |
Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3. The function is able to accept a hostname and return an IP address for th...Show more |