CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Synology 1Application Service Nov 21, 2024 Apr 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the uid parameter. |
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration. |
1Synology 1Diskstation Manager Jan 14, 2025 Apr 1, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configurati...Show more |
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via...Show more |
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path paramete...Show more |
Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_p...Show more |
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain...Show more |
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improp...Show more |
1Microfocus 1Solutions Business Manager Nov 21, 2024 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5. |
1Pfizer 1Lifecare Pca Infusion System Firmware Nov 21, 2024 Mar 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wireless keys are stored in plain text on version 5 of the Hospira LifeCare PCA Infusion System. According to Hospira, version 3 of the LifeCare PCA Infusion System is not indicated for wireless use, is not shipped with...Show more |
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface. |
1Pifzer 3Plum A+3 Infusion System Firmware Plum A+ Infusion System FirmwareSymbiq Infusion System FirmwareNov 21, 2024 Mar 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends th...Show more |
1Opensource Classified Ads Script Project 1Opensource Classified Ads Script Jun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory. |
1Rental Bike Script Project 1Rental Bike Script Jun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory. |
1Image Sharing Script Project 1Image Sharing Script Jun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory. |
1Property Rental Software Project 1Property Rental Software Jun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2016/08 directory. |
1Designchemical 1Social Network Tabs Nov 21, 2024 Mar 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php s...Show more |
1Wp Jobhunt Project 1Wp Jobhunt Nov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enum...Show more |
SaltOS 3.1 r8126 contains a database download vulnerability. |
1Thereceptionist 1The Receptionist For Ipad Nov 21, 2024 Mar 21, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contact.json file. An attacker could exploit this vulnerability to obtain the contact names, phone numbers...Show more |