← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Webex Meetings
Jun 17, 2026
Mar 4, 2020
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the W...Show more
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could exploit this vulnerability by doing an mDNS query for a particular service against an affected device. A successful exploit could allow the attacker to gain access to sensitive information.Show less
3Fasterxml
NetappOracle
4Goldengate Stream Analytics
Jackson DatabindOncommand Api Services+1 more
Jun 17, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction wi...Show more
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.Show less
3Apache
FasterxmlRedhat
8Decision Manager
GeodeJackson Databind+5 more
Jun 17, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.Show less
2Asus
Asuswrt Merlin
2Asus Firmware
Asuswrt Merlin
Jun 17, 2026
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostn...Show more
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network devices' hostnames and MAC addresses by reading the custom_id variable on the blocking.asp page.Show less
2Asus
Asuswrt Merlin
2Asus Firmware
Asuswrt Merlin
Jun 17, 2026
Feb 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ran...Show more
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to acquire information on internal network IP address ranges by reading the new_lan_ip variable on the error_page.htm page.Show less
1Golfbuddyglobal
1Course Manager
Jun 17, 2026
Feb 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
1Buddypress
1Buddypress
Jun 17, 2026
Feb 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
1F5
14Arx
Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+11 more
Nov 21, 2024
Feb 21, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain pl...Show more
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.Show less
2Debian
Netsurf Browser
2Debian Linux
Netsurf
Nov 21, 2024
Feb 21, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
1Otrs
1Otrs
Nov 21, 2024
Feb 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid ag...Show more
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.Show less
1Otrs
2Otrs
Otrs Itsm
Nov 21, 2024
Feb 21, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does...Show more
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.Show less
1Zte
1Zxv10 W300 Firmware
Nov 21, 2024
Feb 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Feb 20, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
1Redhat
1Ansible
Nov 21, 2024
Feb 20, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.
1Openstack
1Nova
Nov 21, 2024
Feb 19, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens use...Show more
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.Show less
1Wpcentral
1Wpcentral
Jun 17, 2026
Feb 17, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
1Gitlab
1Gitlab
Jun 17, 2026
Feb 14, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
1Gitlab
1Gitlab
Jun 17, 2026
Feb 14, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
1Lenovo
1Xclarity Administrator
Jun 17, 2026
Feb 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, licens...Show more
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.Show less
1Aicorporation
1Risknet Acquirer
Nov 21, 2024
Feb 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.