← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to...Show more
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubs...Show more
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests.Show less
1Simplehrm
1Simplehrm
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie.
1Sylius
1Syliusresourcebundle
Jun 17, 2026
Jan 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more...Show more
Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API. Anyone exposing an API with ResourceBundle's controller is affected. The vulnerable versions are: <1.3 || >=1.3.0 <=1.3.12 || >=1.4.0 <=1.4.5 || >=1.5.0 <=1.5.0 || >=1.6.0 <=1.6.2. The patch is provided for Sylius ResourceBundle 1.3.13, 1.4.6, 1.5.1 and 1.6.3, but not for any versions below 1.3.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Jan 27, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
1Vivotek
1Pt7135 Firmware
Nov 21, 2024
Jan 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text.
1Bigswitch
3Big Cloud Fabric
Big Monitoring FabricMulti Cloud Director
Jun 17, 2026
Jan 24, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5....Show more
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. A read-only user can access sensitive information via an API endpoint that reveals session cookies of authenticated administrators, leading to privilege escalation.Show less
1Mysecureshell Project
1Mysecureshell
Nov 21, 2024
Jan 23, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
mysecureshell 1.31: Local Information Disclosure Vulnerability
1Vanillaforums
1Vanilla
Nov 21, 2024
Jan 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
1Samsung
10Galaxy Gear Firmware
Gear 2 FirmwareGear Fit 2 Firmware+7 more
Nov 21, 2024
Jan 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based fi...Show more
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.Show less
1Linux
1Tizen
Nov 21, 2024
Jan 22, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, an...Show more
The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.Show less
1Mirc
1Mirc
Nov 21, 2024
Jan 21, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
1Yopify
1Yopify
Nov 21, 2024
Jan 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent purchase data of customers, all without user authorization.
1Cayintech
1Smp Pro4 Firmware
Jun 17, 2026
Jan 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This password is shown in the webpass parameter of a media_folder.cgi?apply_mode=...Show more
An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This password is shown in the webpass parameter of a media_folder.cgi?apply_mode=ping_server URI.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 13, 2020
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.
1Zohocorp
1Manageengine Eventlog Analyzer
Nov 21, 2024
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
1Ricoh
52M 2700 Firmware
M 2701 FirmwareM C250fw Firmware+49 more
Jun 17, 2026
Jan 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jan 10, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 166355.
1Dompdf Project
1Dompdf
Nov 21, 2024
Jan 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
DOMPDF before 0.6.2 allows Information Disclosure.
1Md Systems
1Simplenews
Nov 21, 2024
Jan 9, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allo...Show more
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.Show less