CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Accio Responsive Onepage Parallax Site Template Project 1Accio Responsive Onepage Parallax Site Template Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) v...Show more |
1Accio One Page Parallax Responsive Theme Project 1Accio One Page Parallax Responsive Theme Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct reques...Show more |
1Invento / Architecture Building Agency Template Project 1Invento / Architecture Building Agency Template Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) v...Show more |
1Car Dealer / Auto Dealer Responsive Project 1Car Dealer / Auto Dealer Responsive Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct reque...Show more |
1Diplomat | Political Project 1Diplomat | Political Nov 21, 2024 Oct 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-c...Show more |
1Microsoft 1Open Enclave Software Development Kit Jun 17, 2026 Oct 10, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. |
1Microsoft 2Windows 7 Windows Server 2008Jun 17, 2026 Oct 10, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI...Show more |
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Oct 10, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'. |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Oct 10, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1345. |
1Socomec 1Diris A 40 Firmware Jun 17, 2026 Oct 9, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI. |
1Ibm 1Security Key Lifecycle Manager Jun 17, 2026 Oct 4, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165136. |
In the Screen Lock, there is a possible information disclosure due to an unusual root cause. In certain circumstances, the setting to hide the unlock pattern can be ignored. Product: AndroidVersions: Android-10Android ID...Show more |
In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.STATE_CHANGE intents. This could lead to local information disclosure with no additional execution pr...Show more |
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing pro...Show more |
1Honeywell 59H2w2pc1m Firmware H2w2per3 FirmwareH2w4per3 Firmware+56 moreJun 17, 2026 Sep 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Vi...Show more |
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffi...Show more |
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality,...Show more |
1Jenkins 1Project Inheritance Jun 17, 2026 Sep 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin. |
1Home Assistant 1Home Assistant Nov 21, 2024 Sep 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py. |