CWE-200
10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,459)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Guardium Data Encryption Jun 17, 2026 May 5, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer heade...Show more |
1Cisco 1Catalyst Sd Wan Manager Jun 17, 2026 May 4, 2022 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An au...Show more |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9....Show more |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 May 4, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own scope. |
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater. |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreJun 17, 2026 Apr 29, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of intern...Show more |
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization. |
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. |
1Sonicwall 49Nsa 2650 Firmware Nsa 2700 FirmwareNsa 3650 Firmware+46 moreJun 17, 2026 Apr 27, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext. |
1Sonicwall 49Nsa 2650 Firmware Nsa 2700 FirmwareNsa 3650 Firmware+46 moreJun 17, 2026 Apr 27, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user. |
1Bender 5Cc612 Firmware Cc613 FirmwareIcc15xx Firmware+2 moreJun 17, 2026 Apr 27, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface. |
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Con...Show more |
Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to version 1.0.1, the UserBookmarkSerializer serialized the whole User / Group object, which leaked some...Show more |
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of...Show more |
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The v...Show more |
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`...Show more |
1Vikwp 1Vikbooking Hotel Booking Engine & Property Management System Plugin Jun 17, 2026 Apr 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search...Show more |
The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5. |
A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality. |
In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat. |