← Back
CWE-200

10,489 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,489)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
4Mdm9650 Firmware
Mdm9655 FirmwareSd 835 Firmware+1 more
Nov 21, 2024
Jan 3, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660.
1Huawei
6Hg8010h Firmware
Hg8040h FirmwareHg8045q Firmware+3 more
Jun 17, 2026
Jan 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
There is an information leak vulnerability in some Huawei HG products. An attacker may obtain information about the HG device by exploiting this vulnerability.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI.
1Lfdycms
1Lei Feng Tv Cms
Nov 21, 2024
Dec 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.
1Leagoo
1Z5c Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode...Show more
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) containing an exported content provider named com.android.messaging.datamodel.MessagingContentProvider. Any app co-located on the device can read the most recent text message from each conversation. That is, for each phone number where the user has either sent or received a text message from, a zero-permission third-party app can obtain the body of the text message, phone number, name of the contact (if it exists), and a timestamp for the most recent text message of each conversation. As the querying of the vulnerable content provider app component can be performed silently in the background, a malicious app can continuously monitor the content provider to see if the current message in each conversation has changed to obtain new text messages.Show less
1Leagoo
1Z5c Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode...Show more
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) with an exported broadcast receiver app component named com.android.messaging.trackersender.TrackerSender. Any app co-located on the device, even one with no permissions, can send a broadcast intent with certain embedded data to the exported broadcast receiver application component that will result in the programmatic sending of a text message where the phone number and body of the text message is controlled by the attacker.Show less
1Asus
1Zenfone 3 Max Firmware
Nov 21, 2024
Dec 28, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed app with a package name of com.asus.logupl...Show more
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed app with a package name of com.asus.loguploader (versionCode=1570000275, versionName=7.0.0.55_170515). This app contains an exported service app component named com.asus.loguploader.LogUploaderService that, when accessed with a particular action string, will write a bugreport (kernel log, logcat log, and the state of system services including the text of active notifications), Wi-Fi Passwords, and other system data to external storage (sdcard). Any app with the READ_EXTERNAL_STORAGE permission on this device can read this data from the sdcard after it has been dumped there by the com.asus.loguploader. Third-party apps are not allowed to directly create a bugreport or access the user's stored wireless network credentials.Show less
1Damicms
1Damicms
Nov 21, 2024
Dec 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file.
2Debian
Linux
2Debian Linux
Linux Kernel
Nov 21, 2024
Dec 27, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read...Show more
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via an SIOCFINDIPDDPRT ioctl call.Show less
1Nec
1Univerge Sv9100 Webpro Firmware
Nov 21, 2024
Dec 26, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.
1Gnu
1Wget
Nov 21, 2024
Dec 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensit...Show more
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.Show less
1S Cms
1S Cms
Nov 21, 2024
Dec 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.
1Synology
1Diskstation Manager
Jun 17, 2026
Dec 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.
1Photorange Photo Vault Project
1Photorange Photo Vault
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html...Show more
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.Show less
2D Link
Dlink
18Dcs 2102 Firmware
Dcs 2121 FirmwareDcs 2630l Firmware+15 more
Nov 21, 2024
Dec 20, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L,...Show more
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many affected firmware versions starting from 1.00 and above. The configuration file can be accessed remotely through: <Camera-IP>/common/info.cgi, with no authentication. The configuration file include the following fields: model, product, brand, version, build, hw_version, nipca version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker, and sensor settings.Show less
1Elastic
1Elasticsearch
Nov 21, 2024
Dec 20, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for...Show more
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.Show less
1Pulsesecure
1Virtual Traffic Manager
Nov 21, 2024
Dec 20, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.