CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 18D7800 Firmware Ex2700 FirmwareLbr1020 Firmware+15 moreJun 17, 2026 Dec 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial number, which can be used for a password reset. This affects D7800 before 1.0.1.66, EX2700 before 1.0....Show more |
1Netgear 3Rax35 Firmware Rax38 FirmwareRax40 FirmwareJun 17, 2026 Dec 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102. |
3Fedoraproject Podman ProjectRedhat3Enterprise Linux FedoraPodmanJun 17, 2026 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on p...Show more |
1Ibm 1Cloud Pak For Security Jun 17, 2026 Dec 22, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID...Show more |
Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low privileges could potentially exploit this vulnerability in order to access sensitive...Show more |
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if it included malicious external entity calls, may reveal sensitive information. |
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 16, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak. |
In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inf...Show more |
In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead...Show more |
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel attack where strings in private source code could be guessed by an authenticated but unauthorized ac...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Dec 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610. |
An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repo...Show more |
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to ge...Show more |
The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attacker to discover a target user's IP address (when knowing only their Tox Id) by positioning themselve...Show more |
1Huntflow 1Huntflow Enterprise Jun 17, 2026 Dec 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attack...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Dec 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. |
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance confi...Show more |
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission. |
1Fortinet 1Fortiauthenticator Jun 17, 2026 Dec 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker...Show more |