CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan. |
mediawiki allows deleted text to be exposed |
D-Link DIR-865L has Information Disclosure. |
1Ibm 2Cloud Orchestrator Cloud Orchestrator EnterpriseJun 17, 2026 Oct 24, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry UaaJun 17, 2026 Oct 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content whic...Show more |
Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate attackers to view slices of previously transmitted packets or portions of memory...Show more |
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. |
1Cisco 2Spa112 Firmware Spa122 FirmwareJun 17, 2026 Oct 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulne...Show more |
1Cisco 2Spa112 Firmware Spa122 FirmwareJun 17, 2026 Oct 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulne...Show more |
1Cisco 2Spa112 Firmware Spa122 FirmwareJun 17, 2026 Oct 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. T...Show more |
Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some sensitive encrypted information in the images it creates. A privileged user of a system running an o...Show more |
In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching optimization. This could lead to local information disclosure with no additional execution privileges...Show more |
1Smartit Premium Responsive Project 1Smartit Premium Responsive Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for th...Show more |
1Blessing Premium Responsive Project 1Blessing Premium Responsive Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for t...Show more |
1Gamestheme Premium Project 1Gamestheme Premium Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-con...Show more |
1Goodnex Premium Responsive Project 1Goodnex Premium Responsive Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for th...Show more |
1Almera Responsive Portfolio Site Template Project 1Almera Responsive Portfolio Site Template Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a di...Show more |
1Almera Responsive Portfolio Project 1Almera Responsive Portfolio Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for t...Show more |
1Axioma Premium Responsive Project 1Axioma Premium Responsive Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the...Show more |