← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Application Service
Nov 21, 2024
Apr 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the uid parameter.
1Synology
1Router Manager
Nov 21, 2024
Apr 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.
1Synology
1Diskstation Manager
Jan 14, 2025
Apr 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configurati...Show more
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration.Show less
1Synology
1Router Manager
Nov 21, 2024
Apr 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via...Show more
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.Show less
1Synology
1Router Manager
Nov 21, 2024
Apr 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path paramete...Show more
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.Show less
1Synology
1File Station
Nov 21, 2024
Apr 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_p...Show more
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.Show less
1Redhat
1Ansible Tower
Jun 17, 2026
Mar 28, 2019
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain...Show more
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.Show less
1Cisco
2Ios
Ios Xe
Jun 17, 2026
Mar 28, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improp...Show more
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed at encryption time, when affected software handles configuration updates. An attacker could exploit this vulnerability by retrieving the contents of specific memory locations of an affected device. A successful exploit could result in the disclosure of keying materials that are part of the device configuration, which can be used to recover critical system information.Show less
1Microfocus
1Solutions Business Manager
Nov 21, 2024
Mar 27, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
1Pfizer
1Lifecare Pca Infusion System Firmware
Nov 21, 2024
Mar 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless use, is not shipped with...Show more
Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless use, is not shipped with wireless capabilities, and should not be modified to be used in a wireless capacity in a clinical setting. Hospira has developed a new version of the PCS Infusion System, version 7.0 that addresses the identified vulnerabilities. Version 7.0 has Port 20/FTP and Port 23/TELNET closed by default to prevent unauthorized access.Show less
1Redhat
1Ovirt Engine
Nov 21, 2024
Mar 25, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
1Pifzer
3Plum A+3 Infusion System Firmware
Plum A+ Infusion System FirmwareSymbiq Infusion System Firmware
Nov 21, 2024
Mar 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends th...Show more
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.Show less
1Opensource Classified Ads Script Project
1Opensource Classified Ads Script
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.
1Rental Bike Script Project
1Rental Bike Script
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.
1Image Sharing Script Project
1Image Sharing Script
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.
1Property Rental Software Project
1Property Rental Software
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2016/08 directory.
1Designchemical
1Social Network Tabs
Nov 21, 2024
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php s...Show more
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.Show less
1Wp Jobhunt Project
1Wp Jobhunt
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enum...Show more
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.Show less
1Saltos
1Saltos
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SaltOS 3.1 r8126 contains a database download vulnerability.
1Thereceptionist
1The Receptionist For Ipad
Nov 21, 2024
Mar 21, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contact.json file. An attacker could exploit this vulnerability to obtain the contact names, phone numbers...Show more
The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contact.json file. An attacker could exploit this vulnerability to obtain the contact names, phone numbers and emails.Show less