CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Abb 5System Access Point 127v Firmware System Access Point 2.0 FirmwareWl System Access Point 127v Firmware+2 moreJun 17, 2026 Sep 23, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point. |
1Amd 2Chipset Driver Psp DriverJun 17, 2026 Sep 21, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to th...Show more |
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. Howe...Show more |
1Motopress 1Timetable And Event Schedule Jun 17, 2026 Sep 20, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (along other less sensitive data) of the user related to the Even Head of the Timeslot in the respons...Show more |
3Apache DebianOracle18Agile Plm Commerce Guided SearchCommerce Platform+15 moreJun 17, 2026 Sep 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference e...Show more |
1Ait Pro 1Bulletproof Security Jun 17, 2026 Sep 17, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the si...Show more |
1Hashicorp 1Terraform Enterprise Jun 17, 2026 Sep 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a...Show more |
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workar...Show more |
1Ibm 1Security Secret Server Jun 17, 2026 Sep 14, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser hi...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Sep 14, 2021 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve a list of network...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Sep 14, 2021 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has an information disclosure vulnerability that could allow an attacker to retrieve VPN connection for...Show more |
Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 9, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions,...Show more |
An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak. |
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow. This vulnerability is due to insufficient application of restrictions du...Show more |
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information Disclosure vulnerability when uploading a modified png file to a product image. Successful exploita...Show more |
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially va...Show more |
1Ntracker 1Ntracker Usb Enterprise Jun 17, 2026 Sep 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information...Show more |
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version...Show more |