← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Campbellsci
5Cr1000 Firmware
Cr3000 FirmwareCr300 Firmware+2 more
Jun 17, 2026
Jan 26, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the m...Show more
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project m...Show more
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all versions starting from 15.6 before 15.6.1. It was possible for a project maintainer to leak a webhook secret token by changing the webhook URL to an endpoint that allows them to capture request headers.Show less
1Vmware
1Vrealize Log Insight
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.
1Signal
1Signal Desktop
Jun 17, 2026
Jan 23, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively clea...Show more
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file deletion, an attacker can still recover the file if it was previously replied to in a conversation. (Local filesystem access is needed by the attacker.) NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Jan 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow...Show more
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with suppression rights.Show less
1Ibm
1Cloud Pak For Security
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 216387.
1Bitrix24
1Bitrix24
Jun 17, 2026
Jan 20, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitri...Show more
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php.Show less
1Ibm
1Spectrum Virtualize
Jun 17, 2026
Jan 19, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information to an attacker using man-in-the-middle techniques. IBM X-Force ID: 235408.
1Opentext
1Opentext Extended Ecm
Jun 17, 2026
Jan 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent...Show more
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the parameter requestContext. If this parameter is present, the response includes most of the HTTP headers sent to the server and some of the CGI variables like remote_adde and server_name, which is an information disclosure.Show less
1Dell
8Emc Solutions Enabler Virtual Appliance
Emc Unisphere For PowermaxEmc Unisphere For Powermax Virtual Appliance+5 more
Jun 17, 2026
Jan 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerabil...Show more
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information disclosure vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to read arbitrary files on the underlying file system. Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 17, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It was possible to read repository content by an unauthorised user if a project member used a crafted link.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jan 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed hosts in the deployment that do not require that key. IBM X-Force ID: 244356.
1Freeradius
1Freeradius
Jun 17, 2026
Jan 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.
1Ronds
1Equipment Predictive Maintenance
Jun 17, 2026
Jan 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS...Show more
RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands. Show less
1Eternal Terminal Project
1Eternal Terminal
Jun 17, 2026
Jan 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.
1Alotceriot
1Ar7088h A Firmware
Jun 17, 2026
Jan 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenti...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict public level visibility.Show less
1Cloudflare
1Warp
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile application which could hijack legitimate a...Show more
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile application which could hijack legitimate app and steal potentially sensitive information when installed on the victim's device. Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.
1Systemd Project
1Systemd
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.