← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Squirrelly
1Squirrelly
Jun 17, 2026
May 14, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting int...Show more
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.Show less
1Express Handlebars Project
1Express Handlebars
Jun 17, 2026
May 14, 2021
N/A· v4
6.8 MEDIUM· v3
4.3 MEDIUM· v2
express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclo...Show more
express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications. This potential vulnerability is somewhat restricted in that only files with existing extentions (i.e. file.extension) can be included, files that lack an extension will have .hbs appended to them. For complete details refer to the referenced GHSL-2021-019 report. Notes in documentation have been added to help users of express-hbs avoid this potential information exposure vulnerability.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
May 13, 2021
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain c...Show more
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
May 13, 2021
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile AP...Show more
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile API are normally disabled for an index when document level security is enabled on the index. Certain queries are able to enable the profiler and suggester which could lead to disclosing the existence of documents and fields the attacker should not be able to view.Show less
2Fedoraproject
Sensiolabs
2Fedora
Symfony
Jun 17, 2026
May 13, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether th...Show more
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user exists or not if a user cannot switch to a user or if the user does not exist. The patch for this issue is available for branch 3.4.Show less
1Wago
50852 0303 Firmware
0852 1305/000 001 Firmware0852 1305 Firmware+2 more
Jun 17, 2026
May 13, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
1Redhat
2Jboss Ejb Client
Jboss Enterprise Application Platform Expansion Pack
Jun 17, 2026
May 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data...Show more
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.Show less
1Mongodb
1C Driver
Jun 17, 2026
May 13, 2021
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive dat...Show more
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when commands such as "saslStart", "saslContinue", "isMaster", "createUser", and "updateUser" are executed. Without due care, an application may inadvertently expose this authenticated-related information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C# Driver v2.12 versions prior to and including 2.12.1.Show less
2Debian
Imagemagick
2Debian Linux
Imagemagick
Jun 17, 2026
May 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality.
1Microsoft
2Sharepoint Foundation
Sharepoint Server
Jun 17, 2026
May 11, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Microsoft SharePoint Server Information Disclosure Vulnerability
1Redhat
1Openstack
Jun 17, 2026
May 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data conf...Show more
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.Show less
1Dell
1Hybrid Client
Jun 17, 2026
Apr 30, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to view and exfiltrate sensitive information on the system.
1Dell
1Hybrid Client
Jun 17, 2026
Apr 30, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to register the client to a server in order to view sensiti...Show more
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to register the client to a server in order to view sensitive information.Show less
1Dell
1Hybrid Client
Jun 17, 2026
Apr 30, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to gain access to sensitive information via the local API.
2Debian
Redhat
4Ansible Automation Platform
Ansible EngineAnsible Tower+1 more
Jun 17, 2026
Apr 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attack...Show more
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.Show less
1Miraheze
1Managewiki
Jun 17, 2026
Apr 28, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageWiki variable to all users. This has been patched by https://github.com/...Show more
ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageWiki variable to all users. This has been patched by https://github.com/miraheze/ManageWiki/compare/99f3b2c8af18...befb83c66f5b.patch. If you are unable to patch set `$wgAPIListModules['wikiconfig'] = 'ApiQueryDisabled';` or remove private config as a workaround.Show less
1Meritlilin
41P2g1022 Firmware
P2g1022x FirmwareP2g1052 Firmware+38 more
Jun 17, 2026
Apr 28, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.
1Meritlilin
41P2g1022 Firmware
P2g1022x FirmwareP2g1052 Firmware+38 more
Jun 17, 2026
Apr 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.
1Apache
1Tapestry
Jun 17, 2026
Apr 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-...Show more
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-13953. This issue affects Apache Tapestry Apache Tapestry 5.4.0 version to Apache Tapestry 5.6.3; Apache Tapestry 5.7.0 version and Apache Tapestry 5.7.1.Show less
1Vaadin
2Flow
Vaadin
Jun 17, 2026
Apr 23, 2021
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController