← Back
CWE-200

10,443 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,443)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
1Simcenter Star Ccm+ Viewer
Jul 14, 2026
Aug 10, 2022
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public lice...Show more
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public license server is used. This could allow an attacker to retrieve this information.Show less
1Microsoft
4Windows 10
Windows 11Windows Server 2016+1 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Defender Credential Guard Information Disclosure Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Defender Credential Guard Information Disclosure Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Windows Defender Credential Guard Information Disclosure Vulnerability
1Microsoft
1Exchange Server
Jun 17, 2026
Aug 9, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Microsoft Exchange Server Information Disclosure Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Simple E Learning System Project
1Simple E Learning System
Jun 17, 2026
Aug 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download...Show more
A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205828.Show less
1Tcl
1Linkhub Mesh Wifi Ac1200
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can...Show more
An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.Show less
1Tcl
1Linkhub Mesh Wifi Ac1200
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker c...Show more
An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.Show less
1Arista
1Cloudvision Portal
Jun 17, 2026
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and Syst...Show more
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.Show less
1Samsung
1Samsung Internet Browser
Jun 17, 2026
Aug 5, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.
1Samsung
1Game Launcher
Jun 17, 2026
Aug 5, 2022
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.
1Google
1Android
Jun 17, 2026
Aug 5, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.
1Google
1Android
Jun 17, 2026
Aug 5, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.
1Duraspace
1Dspace
Jun 17, 2026
Aug 1, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the...Show more
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL of the withdrawn Item. This vulnerability only impacts the XMLUI. Users are advised to upgrade to version 6.4 or newer.Show less
1Makedp
1Mprweb
Jun 17, 2026
Aug 1, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the `Hide Email Address` checkbox on their account page, or during signup. T...Show more
mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the `Hide Email Address` checkbox on their account page, or during signup. This could lead to an account's email being leaked, which may be problematic if your email needs to remain private for any reason. Users hosting their own mprweb instance will need to upgrade to the latest commit to get this fixed. Users on the official instance will already have this issue fixed.Show less
1Dpgaspar
1Flask Appbuilder
Jun 17, 2026
Aug 1, 2022
N/A· v4
2.7 LOW· v3
N/A· v2
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings...Show more
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters could be made by using partial hashed password strings. The response would not include the hashed passwords, but an attacker could infer partial password hashes and their respective users. This issue has been fixed in version 4.1.3. Users are advised to upgrade. There are no known workarounds for this issue.Show less
1Synology
1Media Server
Jun 17, 2026
Jul 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.
1Tencent
1Wechat
Jun 17, 2026
Jul 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.