CWE-200
10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,459)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a bo...Show more |
1Redhat 3Business Central Descision ManagerProcess AutomationJun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. |
Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user with standard privilege could potentially exploit this vulnerability and provide incorrect port inf...Show more |
Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious user could potentially exploit this vulnerability in order to view sensitive information from the WM...Show more |
Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof debug and prometheus metrics handlers to untrusted traffic. This can leak potentially sensitive envir...Show more |
1Tem 2Flex 1080 Firmware Flex 1085 FirmwareJun 17, 2026 Mar 29, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware i...Show more |
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoin...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Mar 25, 2022 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO)...Show more |
Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior in the `beta` branch, and 2.9.0.beta3 and prior in the `tests-passed` branch are vulnerable to a dat...Show more |
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially e...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Mar 23, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space. |
2Openstack Redhat2Openstack Tripleo Heat TemplatesJun 17, 2026 Mar 23, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is vi...Show more |
1Ge 19Multilin B30 Firmware Multilin B90 FirmwareMultilin C30 Firmware+16 moreJun 17, 2026 Mar 23, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information. |
1Ge 19Multilin B30 Firmware Multilin B90 FirmwareMultilin C30 Firmware+16 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication. |
Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###AccountedTimeDisplay is disabled. |
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7). |
1Ptc 2Axeda Agent Axeda Desktop ServerJun 17, 2026 Mar 16, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplies the event log of the specific service. |
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0. |
1Sysend.js Project 1Sysend.js Jun 17, 2026 Mar 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that use cross-origin communication may have their communications intercepted. Impact is limited by the co...Show more |
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11,...Show more |