← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
1Sma100 Firmware
Jun 17, 2026
Mar 13, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specified email address. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
1Smartbear
1Swagger Codegen
Jun 17, 2026
Mar 11, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-co...Show more
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between all local users. When files/directories are created, the default `umask` settings for the process are respected. As a result, by default, most processes/apis will create files/directories with the permissions `-rw-r--r--` and `drwxr-xr-x` respectively, unless an API that explicitly sets safe file permissions is used. Because this vulnerability impacts generated code, the generated code will remain vulnerable until fixed manually! This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21363.Show less
1Zope
1Products.genericsetup
Jun 17, 2026
Mar 9, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSetup before version 2.1.1 there is an information disclosure vulnerabilit...Show more
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSetup before version 2.1.1 there is an information disclosure vulnerability - anonymous visitors may view log and snapshot files generated by the Generic Setup Tool. The problem has been fixed in version 2.1.1. Depending on how you have installed Products.GenericSetup, you should change the buildout version pin to 2.1.1 and re-run the buildout, or if you used pip simply do pip install `"Products.GenericSetup>=2.1.1"`.Show less
2Elastic
Oracle
2Communications Cloud Native Core Automated Test Suite
Elasticsearch
Jun 17, 2026
Mar 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query a...Show more
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet refreshed in the index. This could result in the search disclosing the existence of documents and fields the attacker should not be able to view.Show less
2Plone
Zope
2Plone
Products.pluggableauthservice
Jun 17, 2026
Mar 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an information disclosure vulnerability - everyone can list the...Show more
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an information disclosure vulnerability - everyone can list the names of roles defined in the ZODB Role Manager plugin if the site uses this plugin. The problem has been fixed in version 2.6.0. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to 2.6.0 and re-run the buildout, or if you used pip simply do `pip install "Products.PluggableAuthService>=2.6.0"`.Show less
1Samsung
1Pay Mini
Jun 17, 2026
Mar 4, 2021
N/A· v4
2.4 LOW· v3
1.9 LOW· v2
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.
1Samsung
1Pay Mini
Jun 17, 2026
Mar 4, 2021
N/A· v4
2.4 LOW· v3
1.9 LOW· v2
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.
1Samsung
1Pay Mini
Jun 17, 2026
Mar 4, 2021
N/A· v4
2.4 LOW· v3
1.9 LOW· v2
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.
3Apache
DebianOracle
12Agile Plm
Communications Cloud Native Core PolicyCommunications Cloud Native Core Security Edge Protection Proxy+9 more
Jun 17, 2026
Mar 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to...Show more
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.Show less
1Synology
4Diskstation Manager
Diskstation Manager Unified ControllerSkynas Firmware+1 more
Jun 17, 2026
Feb 26, 2021
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickC...Show more
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic.Show less
1Bestit
1Amazon Pay
Jun 17, 2026
Feb 26, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
best it Amazon Pay Plugin before 9.4.2 for Shopware exposes Sensitive Information to an Unauthorized Actor.
1Microfocus
1Solutions Business Manager
Jun 17, 2026
Feb 26, 2021
N/A· v4
3.5 LOW· v3
2.7 LOW· v2
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure.
1Jenkins
1Support Core
Jun 17, 2026
Feb 24, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details only)" information, which can include the session ID of the user creating...Show more
Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details only)" information, which can include the session ID of the user creating the support bundle in some configurations.Show less
1Contec
1Sv Cpt Mc310 Firmware
Jun 17, 2026
Feb 24, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain the information inside the system, such as directories and/or file configura...Show more
Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain the information inside the system, such as directories and/or file configurations via unspecified vectors.Show less
1Brave
1Brave
Jun 17, 2026
Feb 23, 2021
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in Brave 1.17.73 accidentally initiated DNS requests that bypassed the Brav...Show more
Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in Brave 1.17.73 accidentally initiated DNS requests that bypassed the Brave Tor proxy. Users with adblocking enabled would leak DNS requests from Tor windows to their DNS provider. (DNS requests that were not initiated by CNAME adblocking would go through Tor as expected.) This is fixed in Brave version 1.20.108Show less
1Redhat
1Satellite
Jun 17, 2026
Feb 23, 2021
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confident...Show more
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Rangerstudio
1Directus
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as email address, first name, and last name...Show more
In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they get in response a lot of information about the user (such as email address, first name, and last name) but also the secret for 2FA if one exists. This secret can be regenerated. NOTE: This vulnerability only affects products that are no longer supported by the maintainerShow less
1Ibm
1Planning Analytics
Jun 17, 2026
Feb 23, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's internal structure by exposing sensitive information in HTTP repsonses. IBM X-Force ID: 192029.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader+1 more
Jun 17, 2026
Feb 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS int...Show more
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.Show less
1Qualcomm
347Aqt1000 Firmware
Ar8031 FirmwareAr8035 Firmware+344 more
Jun 17, 2026
Feb 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer...Show more
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and NetworkingShow less