← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
2Debian
Redhat
3Ansible
Debian LinuxOpenstack
Jun 17, 2026
Jul 30, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advan...Show more
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Jul 30, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
1Printeron
1Central Print Services
Nov 21, 2024
Jul 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.
1Unity
1Web Player
Nov 21, 2024
Jul 29, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
1Craftcms
1Craft Cms
Jun 17, 2026
Jul 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
1Apache
1Storm
Jun 17, 2026
Jul 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file sy...Show more
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.Show less