CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting int...Show more |
1Express Handlebars Project 1Express Handlebars Jun 17, 2026 May 14, 2021 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclo...Show more |
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain c...Show more |
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Document and Field Level Security are enabled. The suggester and profile AP...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether th...Show more |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory. |
1Redhat 2Jboss Ejb Client Jboss Enterprise Application Platform Expansion PackJun 17, 2026 May 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data...Show more |
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive dat...Show more |
2Debian Imagemagick2Debian Linux ImagemagickJun 17, 2026 May 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in TransformSignature is possible. The highest threat from this vulnerability is to data confidentiality. |
1Microsoft 2Sharepoint Foundation Sharepoint ServerJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Microsoft SharePoint Server Information Disclosure Vulnerability |
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data conf...Show more |
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to view and exfiltrate sensitive information on the system. |
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to register the client to a server in order to view sensiti...Show more |
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker may exploit this vulnerability in order to gain access to sensitive information via the local API. |
2Debian Redhat4Ansible Automation Platform Ansible EngineAnsible Tower+1 moreJun 17, 2026 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attack...Show more |
ManageWiki is an extension to the MediaWiki project. The 'wikiconfig' API leaked the value of private configuration variables set through the ManageWiki variable to all users. This has been patched by https://github.com/...Show more |
1Meritlilin 41P2g1022 Firmware P2g1022x FirmwareP2g1052 Firmware+38 moreJun 17, 2026 Apr 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential. |
1Meritlilin 41P2g1022 Firmware P2g1022x FirmwareP2g1052 Firmware+38 moreJun 17, 2026 Apr 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices. |
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files inside WEB-INF if using a specially-constructed URL. This was caused by an incomplete fix for CVE-2020-...Show more |
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 through 15.0.4) may expose sensitive data if the application also uses e.g. @RestController |