CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fp Newsletter Project 1Fp Newsletter Jun 17, 2026 Dec 14, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obta...Show more |
1Fp Newsletter Project 1Fp Newsletter Jun 17, 2026 Dec 14, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obta...Show more |
TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are subject to Sensitive Information Disclosure. Due to the lack of handling user-submitted YAML pla...Show more |
1Siemens 56gk5204 0ba00 2kb2 Firmware 6gk5204 0ba00 2mb2 Firmware6gk5204 0bs00 2na3 Firmware+2 moreJun 17, 2026 Dec 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All v...Show more |
In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notifications on the lockscreen due to an incorrect state transition. This could lead to local information di...Show more |
1Hpe 9Hf20 Firmware Hf20c FirmwareHf20h Firmware+6 moreJun 17, 2026 Dec 12, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary Flash Arrays which could potentially allow local disclosure of sensitive information.
|
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are co...Show more |
FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition to user preferences, such configurations contain hashed passwords (brypt with cost 9, salted) of Fr...Show more |
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without approp...Show more |
Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulnerability in Traefik displaying the Authorization header in its debug logs. In certain cases, if the...Show more |
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects. |
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information. |
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information. |
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log. |
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number. |
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log. |
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure. |
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure. |
5Apple DebianHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Dec 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was us...Show more |
AMI MegaRAC User Enumeration Vulnerability |