CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. |
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors...Show more |
uzbl: Information disclosure via world-readable cookies storage file |
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users |
2Debian Suckless2Debian Linux SurfNov 21, 2024 Nov 19, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 surf: cookie jar has read access from other local user |
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by...Show more |
3Clamav DebianFedoraproject3Clamav Debian LinuxFedoraNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ClamAV before 0.97.7: dbg_printhex possible information leak |
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially discl...Show more |
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN. |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs. |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Moodle before 2.2.2: Overview report allows users to see hidden courses |
2Fedoraproject Moodle2Fedora MoodleNov 21, 2024 Nov 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export |
4Debian FedoraprojectMoodle+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to |
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are...Show more |
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request. |
1Slack Chat Project 1Slack Chat Jun 17, 2026 Nov 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.). |
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.). |
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.). |
1Microsoft 6Excel Excel ServicesOffice+3 moreJun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'. |