← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Brother
1Mfc 9970cdw Firmware
Nov 21, 2024
Feb 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information.
1Joomla
1Joomla
Nov 21, 2024
Feb 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
1Apple
2Mac Os X
Safari
Nov 21, 2024
Feb 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
1Brother
1Mfc 9970cdw Firmware
Nov 21, 2024
Feb 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer heade...Show more
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.Show less
1Tinywebgallery
1Tinywebgallery
Nov 21, 2024
Feb 3, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page imag...Show more
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.Show less
1Telaen Project
1Telaen
Nov 21, 2024
Feb 3, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request.
1Dynamic Content Elements Project
1Dynamic Content Elements
Nov 21, 2024
Feb 3, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.
1Linux
1Linux Kernel
Jun 17, 2026
Jan 31, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a...Show more
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.Show less
3Abrt Project
FedoraprojectRedhat
5Abrt
Enterprise Linux DesktopEnterprise Linux Server+2 more
Nov 21, 2024
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ABRT might allow attackers to obtain sensitive information from crash reports.
1Senior
1Rubiweb
Jun 17, 2026
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the correct URL.
1Flippy Project
1Flippy
Nov 21, 2024
Jan 30, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node.
1Veraxsystems
1Network Management System
Nov 21, 2024
Jan 30, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Verax NMS prior to 2.1.0 leaks connection details when any user executes a Repair Table action
1Imagely
1Nextgen Gallery
Nov 21, 2024
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
1Jenkins
1Jenkins
Jun 17, 2026
Jan 29, 2020
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
1Dlink
17Dcs 1100 Firmware
Dcs 1100l FirmwareDcs 1130 Firmware+14 more
Nov 21, 2024
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1...Show more
An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.0, DCS-7410 1.0, DCS-7510 1.0, and WCS-1100 1.02, which could let a malicious user obtain unauthorized access to video streams.Show less
1Dlink
17Dcs 1100 Firmware
Dcs 1100l FirmwareDcs 1130 Firmware+14 more
Nov 21, 2024
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to r...Show more
An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03, which could let a malicious user obtain sensitive information. which could let a malicious user obtain sensitive information.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private...Show more
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.Show less