CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Firepower Extensible Operating System Nx OsJun 17, 2026 Nov 5, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The...Show more |
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API. |
4Debian GnomeOpensuse+1 more4Debian Linux Enterprise LinuxGnome Display Manager+1 moreNov 21, 2024 Nov 5, 2019 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 gdm3 3.14.2 and possibly later has an information leak before screen lock |
Cryptocat has an Unspecified Chat Participant User List Disclosure |
2Kubernetes Redhat2Kube State Metrics Openshift Container PlatformJun 17, 2026 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-...Show more |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend. |
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure |
Cryptocat strophe.js before 2.0.22 has information disclosure |
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure |
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates |
1Infosysta 1In App & Desktop Notifications Jun 17, 2026 Nov 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/n...Show more |
2Debian Miniupnp Project2Debian Linux MiniupnpdNov 21, 2024 Nov 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MiniUPnPd has information disclosure use of snprintf() |
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services. |
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is...Show more |
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exist...Show more |
1Schneider Electric 23Modicon M340 Firmware Modicon M580 FirmwareTsxmcpc002m Firmware+20 moreJun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the c...Show more |
1Schneider Electric 3Modicon Bmenoc 0311 Firmware Modicon Bmenoc 0321 FirmwareModicon M580 FirmwareJun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST...Show more |
1Schneider Electric 3Modicon Bmenoc 0311 Firmware Modicon Bmenoc 0321 FirmwareModicon M580 FirmwareJun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided b...Show more |
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosin...Show more |
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with va...Show more |