← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wizconnected
1A60 Colors Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the priva...Show more
An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the privacy of the end user. The information sent includes the local IP address being used and the SSID of the Wi-Fi network the device is connected to. (Various resources such as wigle.net can be use for mapping of SSIDs to physical locations.)Show less
1Wire
1Wire Webapp
Jun 17, 2026
Apr 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock passphrase, the typed passphrase will be...Show more
wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03-15-production.0, when being prompted to enter the app-lock passphrase, the typed passphrase will be sent into the most recently used chat when the user does not actively give focus to the input field. Input element focus is enforced programatically in version 2021-03-15-production.0.Show less
1Node Etsy Client Project
1Node Etsy Client
Jun 17, 2026
Apr 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-client v0.3.0 and later.
8Broadcom
DebianFedoraproject+5 more
12Communications Billing And Revenue Management
Debian LinuxEssbase+9 more
Jun 17, 2026
Apr 1, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials f...Show more
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.Show less
3Eclipse
NetappOracle
17Autovue For Agile Product Lifecycle Management
Banking ApisBanking Digital Experience+14 more
Jun 17, 2026
Apr 1, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a r...Show more
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.Show less
5Apache
EclipseFedoraproject+2 more
23Autovue For Agile Product Lifecycle Management
Banking ApisBanking Digital Experience+20 more
Jun 17, 2026
Apr 1, 2021
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadverte...Show more
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.Show less
1Wire
1Wire Server
Jun 17, 2026
Mar 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-02, the client metadata of all users was exposed in the `GET /users/list...Show more
wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16 and before version 2021-03-02, the client metadata of all users was exposed in the `GET /users/list-clients` endpoint. The endpoint could be used by any logged in user who could request client details of any other user (no connection required) as far as they can find their User ID. The exposed metadata included id, class, type, location, time, and cookie. A user on a Wire backend could use this endpoint to find registration time and location for each device for a given list of users. As a workaround, remove `/list-clients` from nginx config. This has been fixed in version 2021-03-02.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Mar 26, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccessible on the releases page
1Samsung
1Android
Jun 17, 2026
Mar 26, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
1Redhat
3389 Directory Server
Directory ServerEnterprise Linux
Jun 17, 2026
Mar 26, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP d...Show more
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.Show less
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Mar 26, 2021
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in...Show more
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in ePO repository and install them on their own machines to have it managed and then in turn get policy details from the ePO server. This can only happen when the ePO Agent Handler is installed in a Demilitarized Zone (DMZ) to service machines not connected to the network through a VPN.Show less
1Samsung
1Account
Jun 17, 2026
Mar 25, 2021
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.
1Acquia
1Mautic
Jun 17, 2026
Mar 23, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Ma...Show more
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing parts of the application.Show less
1Openmicroscopy
1Omero.web
Jun 17, 2026
Mar 23, 2021
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these...Show more
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0.Show less
1Zoom
1Zoom
Jun 17, 2026
Mar 18, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific ap...Show more
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other meeting participants can briefly see contents of other application windows that were explicitly not shared. The contents of these other windows can (for instance) be seen for a short period of time when they overlay the shared window and get into focus. (An attacker can, of course, use a separate screen-recorder application, unsupported by Zoom, to save all such contents for later replays and analysis.) Depending on the unintentionally shared data, this short exposure of screen contents may be a more or less severe security issue.Show less
1Qualcomm
401Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+398 more
Jun 17, 2026
Mar 17, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto...Show more
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and NetworkingShow less
1Qualcomm
401Apq8009 Firmware
Apq8009w FirmwareApq8017 Firmware+398 more
Jun 17, 2026
Mar 17, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Sn...Show more
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and NetworkingShow less
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 15, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
1Hamilton Medical
1Hamilton T1 Firmware
Jun 17, 2026
Mar 15, 2021
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs to get valid checksums...Show more
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs to get valid checksums for tampered configuration files.Show less
1Argoproj
1Argo Cd
Jun 17, 2026
Mar 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the system, and this endpoint is not protected with authentication.