← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Firepower Extensible Operating System
Nx Os
Jun 17, 2026
Nov 5, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The...Show more
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to incomplete role-based access control (RBAC) verification. An attacker could exploit this vulnerability by authenticating to the device and issuing a specific CLI diagnostic command with crafted user-input parameters. An exploit could allow the attacker to perform an arbitrary read of a file on the device, and the file may contain sensitive information. The attacker needs valid device credentials to exploit this vulnerability.Show less
1Typo3
1Typo3
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
4Debian
GnomeOpensuse+1 more
4Debian Linux
Enterprise LinuxGnome Display Manager+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
gdm3 3.14.2 and possibly later has an information leak before screen lock
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cryptocat has an Unspecified Chat Participant User List Disclosure
2Kubernetes
Redhat
2Kube State Metrics
Openshift Container Platform
Jun 17, 2026
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-...Show more
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.Show less
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cryptocat strophe.js before 2.0.22 has information disclosure
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
1Redhat
1Update Infrastructure
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
1Infosysta
1In App & Desktop Notifications
Jun 17, 2026
Nov 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/n...Show more
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.Show less
2Debian
Miniupnp Project
2Debian Linux
Miniupnpd
Nov 21, 2024
Nov 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MiniUPnPd has information disclosure use of snprintf()
1Redhat
1Icedtea6
Nov 21, 2024
Oct 31, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
1Clipsoft
1Rexpert
Jun 17, 2026
Oct 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is...Show more
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is required.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Oct 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exist...Show more
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.Show less
1Schneider Electric
23Modicon M340 Firmware
Modicon M580 FirmwareTsxmcpc002m Firmware+20 more
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the c...Show more
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol.Show less
1Schneider Electric
3Modicon Bmenoc 0311 Firmware
Modicon Bmenoc 0321 FirmwareModicon M580 Firmware
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST...Show more
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.Show less
1Schneider Electric
3Modicon Bmenoc 0311 Firmware
Modicon Bmenoc 0321 FirmwareModicon M580 Firmware
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided b...Show more
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.Show less
1Mediawiki
1Abusefilter
Jun 17, 2026
Oct 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosin...Show more
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFilter filters were viewable (or their differences were viewable) to unprivileged users, thus disclosing potentially sensitive information.Show less
1Mediawiki
1Checkuser
Jun 17, 2026
Oct 29, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with va...Show more
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within oversighted edit summaries made available via the MediaWiki API was potentially visible to users with various levels of access to this extension. Said users should not have been able to view these oversighted edit summaries via the MediaWiki API.Show less