CWE-200
10,443 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,443)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nextcloud 2Nextcloud Enterprise Server Nextcloud ServerJun 17, 2026 Sep 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to accoun...Show more |
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. It was found that in affe...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Sep 13, 2022 N/A· v4 5.2 MEDIUM· v3 N/A· v2 Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs t...Show more |
Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the backend administration contained sensitive data like the hashed password and the session ID. These fiel...Show more |
1Dell 25Chengming 3900 Firmware Inspiron 14 Plus 7420 FirmwareInspiron 16 Plus 7620 Firmware+22 moreJun 17, 2026 Sep 12, 2022 N/A· v4 2.3 LOW· v3 N/A· v2 Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potentially exploit this vulnerability in order access sensitive state information on the system. |
Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log. |
Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log. |
Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a specially crafted URL. |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields (keys used internally by Parse Server, prefixed by `_`) and protected fields (user defined) can be u...Show more |
1Wp Libre Form Project 1Wp Libre Form Jun 17, 2026 Sep 6, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8. |
1Cerber 1Wp Cerber Security, Anti Spam & Malware Scan Jun 17, 2026 Sep 6, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied...Show more |
1Transposh 1Transposh Wordpress Translation Jun 17, 2026 Sep 6, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions check...Show more |
Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure...Show more |
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev |
2Podman Project Redhat3Enterprise Linux Server Enterprise Linux WorkstationPodmanJun 17, 2026 Sep 1, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:505...Show more |
1Stop Spam Comments Project 1Stop Spam Comments Jun 17, 2026 Aug 29, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preventing abuse of comment section, allowing threat authors to easily collect the value and add it to th...Show more |
2Convert2rhel Project Redhat2Convert2rhel Enterprise LinuxJun 17, 2026 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users loc...Show more |
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace. |
An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information. |
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to ac...Show more |