← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Extreme Scale
Jun 17, 2026
Jan 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser histor...Show more
IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 177932.Show less
1Ibm
1Cloud Pak System
Jun 17, 2026
Jan 4, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.
1Vasyltech
1Advanced Access Manager
Jun 17, 2026
Jan 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security prob...Show more
The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).Show less
1Joomla
1Joomla
Jun 17, 2026
Dec 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
1Parallels
1Remote Application Server
Jun 17, 2026
Dec 25, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client fo...Show more
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the login form, it would automatically send a second request to a RASHTML5Gateway/socket.io URI with something like "host":"192.168.###.###" in the POST data.Show less
1Moxa
1Nport Iaw5000a I/o Firmware
Jun 17, 2026
Dec 23, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authorization.
1Phoenixcontact
1Plcnext Firmware
Jun 17, 2026
Dec 17, 2020
N/A· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
1Ibm
1Financial Transaction Manager For Multiplatform
Jun 17, 2026
Dec 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog. This information could be used in further attacks against the system.
1Adremsoft
1Netcrunch
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
1Google
1Android
Jun 17, 2026
Dec 15, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional ex...Show more
In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-158484516Show less
1Siemens
1Xhq
Jun 17, 2026
Dec 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive information about the server's architecture. This could allow an attacker to adapt further attacks...Show more
A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive information about the server's architecture. This could allow an attacker to adapt further attacks to the version in place.Show less
9Apple
DebianFedoraproject+6 more
22Clustered Data Ontap
Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+19 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherw...Show more
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.Show less
4Debian
HaxxSiemens+1 more
5Curl
Debian LinuxSimatic Tim 1531 Irc Firmware+2 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
1Gehealthcare
1111.5t Brivo Mr355 Firmware
3.0t Signa Hd 16 Firmware3.0t Signa Hd 23 Firmware+108 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
1Cisco
2Jabber
Jabber For Mobile Platforms
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 11, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.
1Gitlab
1Gitlab
Jun 17, 2026
Dec 11, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
1Gitlab
1Gitlab
Jun 17, 2026
Dec 11, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.
1Apple
6Icloud
IpadosItunes+3 more
Jun 17, 2026
Dec 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS...Show more
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0. A remote attacker may be able to leak memory.Show less
4Apache
DebianNetapp+1 more
12Blockchain Platform
Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Policy+9 more
Jun 17, 2026
Dec 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 c...Show more
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.Show less