CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked. |
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated. |
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device. |
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116). |
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115). |
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114). |
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133). |
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154). |
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192). |
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186). |
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185). |
27Anynines ApigeeAppdynamics+24 more55Application Analytics Application MonitoringApplication Performance Monitoring+52 moreJun 17, 2026 Aug 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more |
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207). |
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201). |
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin...Show more |
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239). |
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234). |
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290). |
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). |
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329). |