← Back
CWE-200

10,496 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,496)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Asustor
1Data Master
Nov 21, 2024
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
Dec 4, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to users...Show more
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).Show less
1Intuit
1Quicken 2018
Nov 21, 2024
Dec 3, 2018
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password...Show more
An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An attacker needs to have access to the password-protected files to trigger this vulnerability.Show less
1Drobo
15n2 Firmware
Nov 21, 2024
Dec 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.
1Drobo
15n2 Firmware
Nov 21, 2024
Dec 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.
1Drobo
15n2 Firmware
Nov 21, 2024
Dec 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve diagnostic information via the "name" URL parameter.
1Rubyonrails
1Rails
Nov 21, 2024
Nov 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and ha...Show more
A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify the `content-disposition` and `content-type` parameters which can be used in with HTML files and have them executed inline. Additionally, if combined with other techniques such as cookie bombing and specially crafted AppCache manifests, an attacker can gain access to private signed URLs within a specific storage path. This vulnerability has been fixed in version 5.2.1.1.Show less
1Kde
1Kde Applications
Nov 21, 2024
Nov 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Nov 21, 2024
Nov 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier have a ntlm sso hash theft vulnerability. Successful exploitation could lead to information disclos...Show more
Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier have a ntlm sso hash theft vulnerability. Successful exploitation could lead to information disclosure.Show less
1Huawei
1Fusionsphere Openstack
Jun 17, 2026
Nov 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection for specific services, a remote, unauthorized attacker can exploit this vulnerability to connect to s...Show more
There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection for specific services, a remote, unauthorized attacker can exploit this vulnerability to connect to specific services to obtain additional information. Successful exploitation of this vulnerability can lead to information leakage.Show less
1Huawei
1Emily Al00a Firmware
Jun 17, 2026
Nov 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to access malicious Website or malicious App and register. Due to incorrect processing of the smart SMS ve...Show more
There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to access malicious Website or malicious App and register. Due to incorrect processing of the smart SMS verification code, successful exploitation can cause sensitive information leak.Show less
1Huawei
2Honor 7a Firmware
Honor 9 Lite Firmware
Jun 17, 2026
Nov 27, 2018
N/A· v4
4.3 MEDIUM· v3
1.9 LOW· v2
There is an information leak vulnerability in some Huawei smartphones. An attacker may do some specific configuration in the smartphone and trick a user into inputting some sensitive information. Due to improper design,...Show more
There is an information leak vulnerability in some Huawei smartphones. An attacker may do some specific configuration in the smartphone and trick a user into inputting some sensitive information. Due to improper design, successful exploit may cause some information leak.Show less
1Terra Master
1Terramaster Operating System
Nov 21, 2024
Nov 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session tokens in a world-readable directory.
1Paloaltonetworks
1Expedition
Nov 21, 2024
Nov 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.
1Nvidia
1Geforce Experience
Jun 17, 2026
Nov 27, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.
1Showdoc
1Showdoc
Nov 21, 2024
Nov 27, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
1Buffalo
1Ts5600d1206 Firmware
Nov 21, 2024
Nov 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensitive device information via an unauthenticated POST request.
4Canonical
DebianLinux+1 more
4Debian Linux
Enterprise LinuxLinux Kernel+1 more
Nov 21, 2024
Nov 26, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cle...Show more
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one.Show less
1Ibm
1Cloud Private
Nov 21, 2024
Nov 21, 2018
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible fo...Show more
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data. IBM X-Force ID: 150903Show less
1Royalapplications
2Royal Ts
Royal Tsx
Nov 21, 2024
Nov 20, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure.