CWE-200
10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,459)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Bluproducts LunaWikomobile5G90 Firmware G9 FirmwareSimo Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper writes three IMEI values to system properties at system startup. The system property...Show more |
3Bluproducts LunaWikomobile5G90 Firmware G9 FirmwareSimo Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in plaintext using HTTP to servers located in China: user's list of installed apps and d...Show more |
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affecte...Show more |
It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected |
1Freetakserver Ui Project 1Freetakserver Ui Jun 17, 2026 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys. |
2Debian Spip2Debian Linux SpipJun 17, 2026 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects. |
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log |
Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log |
Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log |
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log |
Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log |
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log. |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access information which would otherwise be restricted. |
1Sap 1Simple Diagnostics Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a random port 9000-65535. This allows information gathering which could be u...Show more |
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section. |
2Fedoraproject Keepass3Extra Packages For Enterprise Linux FedoraKeepassJun 17, 2026 Mar 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive...Show more |
5Debian FedoraprojectLinux+2 more23Codeready Linux Builder Debian LinuxEnterprise Linux+20 moreJun 17, 2026 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memo...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Mar 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a...Show more |
A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible. |
Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can exploit this vulnerability to download part of the files in Xiaomi Router A...Show more |