CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jul 15, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1073. |
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is:...Show more |
On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackability" and "considerable privacy concerns" without a user-accessible ano...Show more |
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Jul 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header o...Show more |
On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter rule first, since it has high priority. This rule is meant for reserved multicast addresses 224.0.0...Show more |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Jul 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153749. |
1Pivotal Software 1Cloud Foundry Uaa Release Jun 17, 2026 Jul 11, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all ot...Show more |
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI. |
1Hp 13par Service Processor Firmware Jun 17, 2026 Jul 9, 2019 N/A· v4 9.8 CRITICAL· v3 9.7 HIGH· v2 HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for...Show more |
Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes. |
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py. |
3Fedoraproject LibosinfoRedhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreJun 17, 2026 Jul 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line. |
In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack m...Show more |
Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local...Show more |
1Cloudera 1Data Science Workbench Nov 21, 2024 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors. |
1Redhat 2Enterprise Linux Virt ManagerJun 17, 2026 Jul 3, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking...Show more |
1Blipcare 1Wi Fi Blood Pressure Monitor Firmware Nov 21, 2024 Jul 2, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP proto...Show more |
1Nortekcontrol 2Linear Emerge Elite Firmware Linear Emerge Essential FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure. |
IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336. |