CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information. |
Joomla! 1.7.1 has core information disclosure due to inadequate error checking. |
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information. |
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer heade...Show more |
1Tinywebgallery 1Tinywebgallery Nov 21, 2024 Feb 3, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page imag...Show more |
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request. |
1Dynamic Content Elements Project 1Dynamic Content Elements Nov 21, 2024 Feb 3, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request. |
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a...Show more |
3Abrt Project FedoraprojectRedhat5Abrt Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jan 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ABRT might allow attackers to obtain sensitive information from crash reports. |
Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the correct URL. |
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node. |
1Veraxsystems 1Network Management System Nov 21, 2024 Jan 30, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Verax NMS prior to 2.1.0 leaks connection details when any user executes a Repair Table action |
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability |
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page. |
1Dlink 17Dcs 1100 Firmware Dcs 1100l FirmwareDcs 1130 Firmware+14 moreNov 21, 2024 Jan 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1...Show more |
1Dlink 17Dcs 1100 Firmware Dcs 1100l FirmwareDcs 1130 Firmware+14 moreNov 21, 2024 Jan 28, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to r...Show more |
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page. |
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information. |
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID. |
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private...Show more |