CWE-200
10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,459)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected versions of shopware do no properly set sensitive HTTP headers to be non-cacheable. If there is an HTTP...Show more |
1Schneider Electric 1Ritto Wiser Door Jun 17, 2026 Mar 9, 2022 N/A· v4 7.6 HIGH· v3 4.8 MEDIUM· v2 A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions) |
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enum...Show more |
Nextcloud talk is a self hosting messaging service. In versions prior to 12.3.0 the Nextcloud Android Talk application did not properly detect the lockscreen state when a call was incoming. If an attacker got physical ac...Show more |
2Fedoraproject Httpie2Fedora HttpieJun 17, 2026 Mar 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for fu...Show more |
1Imdpen 1Video Conferencing With Zoom Jun 17, 2026 Mar 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addre...Show more |
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shesca...Show more |
2Buildah Project Redhat4Buildah Enterprise LinuxEnterprise Linux For Ibm Z Systems+1 moreJun 17, 2026 Mar 3, 2022 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and...Show more |
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Mar 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation...Show more |
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys. |
3Fedoraproject PostgresqlRedhat7Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+4 moreJun 17, 2026 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not requi...Show more |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. |
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access...Show more |
2Debian Scrapy2Debian Linux ScrapyJun 17, 2026 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1. |
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities o...Show more |
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by reques...Show more |
1Node Request Retry Project 1Node Request Retry Jun 17, 2026 Feb 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0. |
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). |
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private informatio...Show more |
3Fedoraproject RedhatSamba3Fedora SambaStorageJun 17, 2026 Feb 21, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. S...Show more |