CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 4R6400 Firmware R7900 FirmwareR8000 Firmware+1 moreNov 21, 2024 Apr 21, 2020 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects R6400 before 1.0.1.24, R7900 before 1.0.1.18, R8000 before 1.0.3.54, and R8500 before 1.0.2.100. |
1Netgear 6R6700 Firmware R7000 FirmwareR7100lg Firmware+3 moreNov 21, 2024 Apr 21, 2020 N/A· v4 6.2 MEDIUM· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7900 before 1.0.1.18, R8000 before 1.0.3.54, and R8500 bef...Show more |
1Redhat 6Jboss Data Grid Jboss Enterprise Application PlatformJboss Fuse+3 moreJun 17, 2026 Apr 21, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize...Show more |
2Linuxfoundation Redhat2Ceph Ceph StorageJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use thi...Show more |
1Netgear 7D8500 Firmware R6400 FirmwareR6900p Firmware+4 moreNov 21, 2024 Apr 20, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects R6400v2 before 1.0.2.32, R7000P/R6900P before 1.0.0.56, R7900 before 1.0.1.18, R8300 before 1.0.2.100_1.0.82, R8500 befo...Show more |
IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force ID: 177937. |
1Qualcomm 23Apq8009 Firmware Apq8053 FirmwareApq8096au Firmware+20 moreJun 17, 2026 Apr 16, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdra...Show more |
NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of administrative credentials. |
NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials. |
1Microsoft 1Research Javascript Cryptography Library Jun 17, 2026 Apr 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially...Show more |
1Microsoft 2Dynamics 365 Business Central Dynamics NavJun 17, 2026 Apr 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successf...Show more |
A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges. |
1Mysyngeryss 1Husky Rtu 6049 E70 Firmware Jun 17, 2026 Apr 14, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability. The affected product is vulnerabl...Show more |
1Dell 5Pc5500 Firmware R1 2210 FirmwareR1 2401 Firmware+2 moreJun 17, 2026 Apr 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an...Show more |
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission is mishandled, sensitive information is disclosed in a world-readable copy of the log file if the e...Show more |
2Canonical Netapp32Aff 8300 Firmware Aff 8700 FirmwareAff A220 Firmware+29 moreJun 17, 2026 Apr 10, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete,...Show more |
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or deb...Show more |
In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which were stored within git. |
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing se...Show more |
Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an EX4300 switch, leaking configuration in...Show more |