← Back
CWE-200

10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,459)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Guardium Data Encryption
Jun 17, 2026
May 5, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer heade...Show more
IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 213855.Show less
1Cisco
1Catalyst Sd Wan Manager
Jun 17, 2026
May 4, 2022
N/A· v4
4.4 MEDIUM· v3
4.9 MEDIUM· v2
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An au...Show more
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system.Show less
1Secomea
4Gatemanager 4250 Firmware
Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 more
Jun 17, 2026
May 4, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9....Show more
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.Show less
1Secomea
4Gatemanager 4250 Firmware
Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 more
Jun 17, 2026
May 4, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope.
1Google
1Fuchsia
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.
4Debian
LinuxNetapp+1 more
11Debian Linux
Enterprise LinuxH300e Firmware+8 more
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of intern...Show more
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.Show less
1Smartptt
1Scada Server
Jun 17, 2026
Apr 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.
1Smartptt
1Scada Server
Jun 17, 2026
Apr 29, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
1Sonicwall
49Nsa 2650 Firmware
Nsa 2700 FirmwareNsa 3650 Firmware+46 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
1Sonicwall
49Nsa 2650 Firmware
Nsa 2700 FirmwareNsa 3650 Firmware+46 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
1Bender
5Cc612 Firmware
Cc613 FirmwareIcc15xx Firmware+2 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.
1Nextcloud
1Nextcloud
Jun 17, 2026
Apr 27, 2022
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Con...Show more
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Contacts permission itself. Version 3.19.0 contains a fix for this issue. There are currently no known workarounds.Show less
1Discourse
1Assign
Jun 17, 2026
Apr 26, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to version 1.0.1, the UserBookmarkSerializer serialized the whole User / Group object, which leaked some...Show more
Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to version 1.0.1, the UserBookmarkSerializer serialized the whole User / Group object, which leaked some private information. The data was only being serialized to people who could view assignment info, which is limited to staff by default. For the vast majority of sites, this data was only leaked to trusted staff member, but for sites with assign features enabled publicly, the data was accessible to more people than just staff. Version 1.0.1 contains a patch. There are currently no known workarounds.Show less
1Elastic
1Kibana
Jun 17, 2026
Apr 21, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of...Show more
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Apr 21, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The v...Show more
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldap_pass is not filtered and when you look at the source code of the rendered page, we can see the password for the root dn. Users are advised to upgrade. There is no known workaround for this issue.Show less
1Humhub
1Humhub
Jun 17, 2026
Apr 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`...Show more
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4. There are no known workarounds for this issue.Show less
1Vikwp
1Vikbooking Hotel Booking Engine & Property Management System Plugin
Jun 17, 2026
Apr 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search...Show more
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.Show less
1Web X
1Be Popia Compliant
Jun 17, 2026
Apr 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5.
1Redhat
1Wildfly
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality.
1Linux
1Linux Kernel
Nov 21, 2024
Apr 18, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.