CWE-200
10,443 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,443)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 1Simcenter Star Ccm+ Viewer Jul 14, 2026 Aug 10, 2022 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public lice...Show more |
1Microsoft 4Windows 10 Windows 11Windows Server 2016+1 moreJun 17, 2026 Aug 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Defender Credential Guard Information Disclosure Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Aug 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Defender Credential Guard Information Disclosure Vulnerability |
1Microsoft 10Windows 10 Windows 11Windows 7+7 moreJun 17, 2026 Aug 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Kernel Information Disclosure Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Aug 9, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Windows Defender Credential Guard Information Disclosure Vulnerability |
Microsoft Exchange Server Information Disclosure Vulnerability |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Aug 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Kernel Information Disclosure Vulnerability |
1Simple E Learning System Project 1Simple E Learning System Jun 17, 2026 Aug 8, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download...Show more |
An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can...Show more |
An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker c...Show more |
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and Syst...Show more |
Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files. |
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction. |
Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal. |
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log. |
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the...Show more |
mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the `Hide Email Address` checkbox on their account page, or during signup. T...Show more |
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings...Show more |
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors. |
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts. |