← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436.
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1440.
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
1Microsoft
2Office
Office 365
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'.
1Microsoft
1Open Enclave Software Development Kit
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
1Hitachi
5Compute Systems Manager
Device ManagerReplication Manager+2 more
Nov 21, 2024
Nov 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
1Ibm
1Cognos Controller
Jun 17, 2026
Nov 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-For...Show more
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 162659.Show less
1Philips
2Tasy Emr
Tasy Webportal
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information.
1Redhat
1Jboss Operations Network
Nov 21, 2024
Nov 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
2Debian
Shibboleth
2Debian Linux
Service Provider
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmod...Show more
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.Show less
1Zte
1Mf910s Firmware
Jun 17, 2026
Nov 7, 2019
N/A· v4
6.2 MEDIUM· v3
1.9 LOW· v2
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is conf...Show more
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can obtain the Telnet remote login password in the reverse way. If Telnet is opened, the attacker can remotely log in to the device through the cracked password, resulting in information leakage. The MF910S was end of service on October 23, 2019, ZTE recommends users to choose new products for the purpose of better security.Show less
2Debian
Eclipse
2Debian Linux
Jetty
Nov 21, 2024
Nov 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dump Servlet information leak in jetty before 6.1.22.
1Typo3
1Typo3
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.
2Debian
Typo3
2Debian Linux
Typo3
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
1Typo3
1Typo3
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.
1Cisco
1Enterprise Chat And Email
Jun 17, 2026
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication...Show more
A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download function of the API. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to download files that other users attach through the chat feature. This vulnerability affects versions prior to 12.0(1)ES1.Show less