← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Samsung Mobile Print
Jun 17, 2026
Jan 9, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.
11password
11password
Nov 21, 2024
Jan 9, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
AgileBits 1Password through 1.0.9.340 allows security feature bypass
1Mozilla
1Firefox
Jun 17, 2026
Jan 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerability affects Firefox < 72.
1Google
1Android
Nov 21, 2024
Jan 8, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which...Show more
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).Show less
1Symantec
1Norton Mobile Security
Nov 21, 2024
Jan 8, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, which could let a local malicious user obtain sensitive information.
1Redhat
4Jboss Enterprise Application Platform
Jboss FuseKeycloak+1 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker...Show more
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.Show less
1Genexis
1Platinum 4410 Firmware
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.
2F5
Ntp
25Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+22 more
Nov 21, 2024
Jan 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.
1Fortinet
1Fortisiem
Jun 17, 2026
Jan 7, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source co...Show more
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.Show less
1Telos
1Automated Message Handling System
Jun 17, 2026
Jan 3, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Hand...Show more
: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 3, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 3, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.
2Debian
Fusionforge
2Debian Linux
Fusionforge
Nov 21, 2024
Jan 2, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to in...Show more
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Dec 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 30, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.
2Debian
Openstack
2Debian Linux
Horizon
Nov 21, 2024
Dec 30, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
1Ibm
1Watston Studio Local
Nov 21, 2024
Dec 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in further attacks against the system. IBM X-Force ID: 145238.
1Karotz
1Api
Nov 21, 2024
Dec 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Karotz API 12.07.19.00: Session Token Information Disclosure
1Oracle
1Jdk
Nov 21, 2024
Dec 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumsta...Show more
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.Show less
1Fastvelocity
1Minify
Jun 17, 2026
Dec 26, 2019
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an...Show more
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.Show less