← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Search Guard
1Search Guard
Jun 17, 2026
Aug 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
1Search Guard
1Search Guard
Jun 17, 2026
Aug 12, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
1Tapplock
1Tapplock Firmware
Nov 21, 2024
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
27Anynines
ApigeeAppdynamics+24 more
55Application Analytics
Application MonitoringApplication Performance Monitoring+52 more
Jun 17, 2026
Aug 5, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin...Show more
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin panel, disclosing its location to potentially unauthorized parties.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
3.5 LOW· v3
2.7 LOW· v2
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).