CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability. |
An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats' functionality allows a user to delete all traces of a chat either by...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Feb 12, 2020 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be...Show more |
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability. |
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer. |
Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability |
1Syska 1Smartlight Rainbow Led Smart Bulb Firmware Nov 21, 2024 Feb 10, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineering, and replay attacks. |
1Blackberry 1Playbook Firmware Nov 21, 2024 Feb 10, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error |
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information |
1Basic Webmail Project 1Basic Webmail Nov 21, 2024 Feb 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses. |
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index....Show more |
1Zohocorp 3Manageengine Applications Manager Manageengine It360Manageengine OpmanagerNov 21, 2024 Feb 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, w...Show more |
1Simplemachines 1Simple Machines Forum Nov 21, 2024 Feb 7, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config. |
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating. |
1Cisco 1Linksys E4200 Firmware Nov 21, 2024 Feb 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information. |
1Netgear 2Wgr614v7 Firmware Wgr614v9 FirmwareNov 21, 2024 Feb 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/W...Show more |
2Gnome Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Feb 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which mig...Show more |
Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site. |
1Hp 3Asset Manager Asset Manager Cloudsystem ChargebackSitescopeNov 21, 2024 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, whic...Show more |
1Ibm 1Security Directory Server Jun 17, 2026 Feb 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-...Show more |