← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectMediawiki+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
1Apache
1Nifi
Jun 17, 2026
Nov 19, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors...Show more
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.Show less
2Debian
Uzbl
2Debian Linux
Uzbl
Nov 21, 2024
Nov 19, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
uzbl: Information disclosure via world-readable cookies storage file
1Mpack Project
1Mpack
Nov 21, 2024
Nov 19, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
2Debian
Suckless
2Debian Linux
Surf
Nov 21, 2024
Nov 19, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
surf: cookie jar has read access from other local user
1Iterm2
1Iterm2
Jun 17, 2026
Nov 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by...Show more
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git repositories.Show less
3Clamav
DebianFedoraproject
3Clamav
Debian LinuxFedora
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ClamAV before 0.97.7: dbg_printhex possible information leak
1Mediawiki
1Abusefilter
Jun 17, 2026
Nov 15, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially discl...Show more
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.Show less
1Netgear
1Wndr4700 Firmware
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2: Overview report allows users to see hidden courses
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
4Debian
FedoraprojectMoodle+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
1Sap
1Diagnostics Agent
Jun 17, 2026
Nov 13, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are...Show more
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.Show less
1Ckeditor
1Ckeditor
Nov 21, 2024
Nov 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
1Slack Chat Project
1Slack Chat
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
1Slack
1Wp Slacksync
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
1Intercom
1Intercom
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
1Microsoft
6Excel
Excel ServicesOffice+3 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.