CWE-200
10,489 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,489)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could b...Show more |
2Arm Trustedfirmware2Arm Trusted Firmware Trusted Firmware AJun 5, 2026 Dec 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information. |
1Schneider Electric 4Modicom Bmxnor0200h Firmware Modicom M340 FirmwareModicom Premium Firmware+1 moreJun 17, 2026 Dec 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes...Show more |
In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine. |
IBM Security Guardium 10.0 and 10.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser hist...Show more |
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is...Show more |
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files. |
1Designmodo 1Wp Maintenance Mode Nov 21, 2024 Dec 14, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Dec 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-m...Show more |
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs becaus...Show more |
3Grafana NetappRedhat7Active Iq Performance Analytics Services Ceph StorageEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions. |
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Di...Show more |
1Ibm 1Security Access Manager Nov 21, 2024 Dec 13, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force...Show more |
1Ibm 1Security Access Manager Nov 21, 2024 Dec 13, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 14970...Show more |
1Siemens 1Simatic Step 7 (tia Portal) Nov 21, 2024 Dec 13, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwo...Show more |
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests...Show more |
Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt. This allows the attacker to gain access to usernames, password hashes, p...Show more |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, refe...Show more |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 140757. |
1F5 16Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+13 moreNov 21, 2024 Dec 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not h...Show more |