CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1440. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Nov 12, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'. |
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'. |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. |
1Microsoft 1Open Enclave Software Development Kit Jun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Nov 12, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'. |
1Hitachi 5Compute Systems Manager Device ManagerReplication Manager+2 moreNov 21, 2024 Nov 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information. |
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-For...Show more |
1Philips 2Tasy Emr Tasy WebportalJun 17, 2026 Nov 8, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information. |
1Redhat 1Jboss Operations Network Nov 21, 2024 Nov 8, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON. |
2Debian Shibboleth2Debian Linux Service ProviderNov 21, 2024 Nov 7, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmod...Show more |
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is conf...Show more |
2Debian Eclipse2Debian Linux JettyNov 21, 2024 Nov 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dump Servlet information leak in jetty before 6.1.22. |
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database. |
2Debian Typo32Debian Linux Typo3Nov 21, 2024 Nov 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 TYPO3 before 4.5.4 allows Information Disclosure in the backend. |
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend. |
1Cisco 1Enterprise Chat And Email Jun 17, 2026 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication...Show more |