CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Sep 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an attacker can see the sensitive information via cache and can open the...Show more |
In Limesurvey before 3.17.14, the entire database is exposed through browser caching. |
An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would...Show more |
An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked...Show more |
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6. |
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths. |
The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details. |
In the Android kernel in sync debug fs driver there is a kernel pointer leak due to the usage of printf with %p. This could lead to local information disclosure with system execution privileges needed. User interaction i...Show more |
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional executi...Show more |
1Cisco 2Industrial Network Director Network Level ServiceJun 17, 2026 Sep 5, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The...Show more |
4Debian LinuxNetapp+1 more6Active Iq Performance Analytics Services Baseboard Management Controller FirmwareDebian Linux+3 moreJun 17, 2026 Sep 4, 2019 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/...Show more |
1Microfocus 1Content Manager Jun 17, 2026 Aug 30, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they w...Show more |
2Androvideo Geovision3Gv Vd8700 Firmware Gv Vr360 FirmwareVd 1 FirmwareJun 17, 2026 Aug 29, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password...Show more |
An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as version, models, via parsing a JavaScript file through admin webUI. |
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database. |
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Nov 21, 2024 Aug 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. |
A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information....Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Aug 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality |
2Debian Otrs2Debian Linux OtrsJun 17, 2026 Aug 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the...Show more |