CWE-200
10,496 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,496)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Yitechnology 1Yi Home Camera Firmware Nov 21, 2024 Nov 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings change, resulting in denial of service....Show more |
1Synology 3Diskstation Manager SkynasVs960hdJan 14, 2025 Oct 31, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the...Show more |
1Nextcloud 1Nextcloud Server Nov 21, 2024 Oct 30, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares. |
1Ibm 1Infosphere Master Data Management Nov 21, 2024 Oct 29, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-F...Show more |
ACME mini_httpd before 1.30 lets remote users read arbitrary files. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 29, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long t...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Oct 26, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace. |
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates/Config/FullUpdateSettings.xml issue. |
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Information Disclosure via /gateway/services/EdgeServiceImpl issue. |
1Qualcomm 5Sd 205 Firmware Sd 210 FirmwareSd 212 Firmware+2 moreNov 21, 2024 Oct 26, 2018 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile in version SD 210/SD 212/SD 205, SD 845, SD 850 |
Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting. |
1Polycom 3Unified Communications Software Vvx 500 FirmwareVvx 601 FirmwareNov 21, 2024 Oct 24, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Busin...Show more |
An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing opened conversation by sending an intent. |
1Qualcomm 8Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+5 moreNov 21, 2024 Oct 23, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/S...Show more |
TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI. |
1Sv3c 1H.264 Poe Ip Camera Firmware Nov 21, 2024 Oct 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireles...Show more |
1Sv3c 1H.264 Poe Ip Camera Firmware Nov 21, 2024 Oct 19, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set wi...Show more |
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. |
1Dell 1Emc Secure Remote Services Nov 21, 2024 Oct 18, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens whic...Show more |
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations. |