← Back
CWE-200

10,495 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,495)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Dec 6, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead to local information disclosure with no additional execution privilege...Show more
In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-114770654.Show less
1Ibm
1Connections
Nov 21, 2024
Dec 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315.
1Ibm
1I2 Enterprise Insight Analysis
Nov 21, 2024
Dec 6, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 141413.
1Intel
1Integrated Performance Primitives
Nov 21, 2024
Dec 5, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to potentially enable information disclosure via local access.
1Dell
1Data Protection | Encryption
Nov 21, 2024
Dec 5, 2018
N/A· v4
4.3 MEDIUM· v3
4.9 MEDIUM· v2
Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulner...Show more
Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.Show less
1Ibm
1Qradar Advisor With Watson
Nov 21, 2024
Dec 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147810.
1Ibm
1Maximo Asset Management
Nov 21, 2024
Dec 5, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Maximo Asset Management 7.6 could allow an authenticated user to enumerate usernames using a specially crafted HTTP request. IBM X-Force ID: 145966.
1Ibm
1Qradar Incident Forensics
Nov 21, 2024
Dec 5, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through Browser Caching.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.
1Gitlab
1Gitlab
Nov 21, 2024
Dec 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpoint.
1Netapp
1Data Ontap
Jun 17, 2026
Dec 4, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Data ONTAP operating in 7-Mode versions prior to 8.2.5P2 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter.