← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Magentocommerce
1Magento
Nov 21, 2024
Feb 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
1Rakuten
1Viber
Nov 21, 2024
Feb 13, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats' functionality allows a user to delete all traces of a chat either by...Show more
An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats' functionality allows a user to delete all traces of a chat either by using a time trigger or by direct request. There is a bug in this functionality which leaves behind photos taken and shared on the secret chats, even after the chats are deleted. These photos will be stored in the device and accessible to all applications installed on the Android device.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Feb 12, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be...Show more
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.Show less
1Google
1Android
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
1Google
1Android
Nov 21, 2024
Feb 12, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.
1Mapway
1Tube Map
Nov 21, 2024
Feb 12, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability
1Syska
1Smartlight Rainbow Led Smart Bulb Firmware
Nov 21, 2024
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineering, and replay attacks.
1Blackberry
1Playbook Firmware
Nov 21, 2024
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
1Hp
1Systems Insight Manager
Nov 21, 2024
Feb 10, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
1Basic Webmail Project
1Basic Webmail
Nov 21, 2024
Feb 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
1Open School
1Open School
Nov 21, 2024
Feb 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index....Show more
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.Show less
1Zohocorp
3Manageengine Applications Manager
Manageengine It360Manageengine Opmanager
Nov 21, 2024
Feb 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, w...Show more
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.Show less
1Simplemachines
1Simple Machines Forum
Nov 21, 2024
Feb 7, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
1Videolan
1Vlc Media Player
Nov 21, 2024
Feb 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
1Cisco
1Linksys E4200 Firmware
Nov 21, 2024
Feb 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.
1Netgear
2Wgr614v7 Firmware
Wgr614v9 Firmware
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/W...Show more
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a different issue than CVE-2012-6340.Show less
2Gnome
Redhat
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
Nov 21, 2024
Feb 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which mig...Show more
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.Show less
1Google
1Chrome
Nov 21, 2024
Feb 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site.
1Hp
3Asset Manager
Asset Manager Cloudsystem ChargebackSitescope
Nov 21, 2024
Feb 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, whic...Show more
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.Show less
1Ibm
1Security Directory Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-...Show more
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623.Show less