← Back
CWE-200

10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,459)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chcnav
1P5e Gnss Firmware
Jun 17, 2026
Jul 18, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the res...Show more
Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jul 14, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could...Show more
A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way user uses BPF for the device such that function nsim_map_alloc_elem being called. A local user could use this flaw to get unauthorized access to some data.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Jul 14, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of th...Show more
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.Show less
1Mattermost
1Mattermost Server
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access some sensitive information by directly accessing the APIs.
1Ibm
2Engineering Lifecycle Optimization Publishing
Engineering Lifecycle Optimization Publishing
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728.
1Convert2rhel Project
1Convert2rhel
Jun 17, 2026
Jul 14, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the CLI to convert2rhel. This could allow unauthorized local users to view t...Show more
In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the CLI to convert2rhel. This could allow unauthorized local users to view the password via the process list while convert2rhel is running. However, this ansible playbook is only an example in the upstream repository and it is not shipped in officially supported versions of convert2rhel.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Jul 12, 2022
N/A· v4
6.0 MEDIUM· v3
6.5 MEDIUM· v2
SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modi...Show more
SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modify the password or import the file into another system causing high impact on confidentiality but a limited impact on the availability and integrity of the application.Show less
1Zulip
1Zulip Server
Jun 17, 2026
Jul 12, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data"...Show more
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessible only to server owners and server administrators, which provides a way to download a "public data" export. While this export is only accessible to administrators, in many configurations server administrators are not expected to have access to private messages and private streams. However, the "public data" export which administrators could generate contained the attachment contents for all attachments, even those from private messages and streams. Zulip Server version 5.4 contains a patch for this issue.Show less
1Linux
1Linux Kernel
Nov 21, 2024
Jul 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.
5Debian
FedoraprojectIntel+2 more
129Core I3 6100 Firmware
Core I3 6100e FirmwareCore I3 6100h Firmware+126 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
6.5 MEDIUM· v3
1.9 LOW· v2
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack r...Show more
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.Show less
1Ibm
1Qradar Network Security
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks against the system. IBM X-Force ID: 174339.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
2Dell
Oracle
6Bsafe Crypto C Micro Edition
Bsafe Micro Edition SuiteDatabase+3 more
Jun 17, 2026
Jul 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
1Unsafe Accessor Project
1Unsafe Accessor
Jun 17, 2026
Jul 11, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data of UA is protected by JVM and others can only access UA via UA's standa...Show more
UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data of UA is protected by JVM and others can only access UA via UA's standard API. The main application can set up `SecurityCheck.AccessLimiter` for UA to limit access to UA. Starting with version 1.4.0 and prior to version 1.7.0, when `SecurityCheck.AccessLimiter` is set up, untrusted code can access UA without limitation, even when UA is loaded as a named module. This issue does not affect those for whom `SecurityCheck.AccessLimiter` is not set up. Version 1.7.0 contains a patch.Show less