← Back
CWE-200

10,496 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,496)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yitechnology
1Yi Home Camera Firmware
Nov 21, 2024
Nov 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings change, resulting in denial of service....Show more
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings change, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability.Show less
1Synology
3Diskstation Manager
SkynasVs960hd
Jan 14, 2025
Oct 31, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the...Show more
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.Show less
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Oct 30, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
1Ibm
1Infosphere Master Data Management
Nov 21, 2024
Oct 29, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-F...Show more
IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.Show less
1Acme
1Mini Httpd
Nov 21, 2024
Oct 29, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Oct 29, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long t...Show more
An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940 and CVE-2018-16658.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Oct 26, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
1Arcserve
1Udp
Nov 21, 2024
Oct 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates/Config/FullUpdateSettings.xml issue.
1Arcserve
1Udp
Nov 21, 2024
Oct 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Information Disclosure via /gateway/services/EdgeServiceImpl issue.
1Qualcomm
5Sd 205 Firmware
Sd 210 FirmwareSd 212 Firmware+2 more
Nov 21, 2024
Oct 26, 2018
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile in version SD 210/SD 212/SD 205, SD 845, SD 850
1Prayer Project
1Prayer
Nov 21, 2024
Oct 26, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.
1Polycom
3Unified Communications Software
Vvx 500 FirmwareVvx 601 Firmware
Nov 21, 2024
Oct 24, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Busin...Show more
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.Show less
1Conversations
1Conversations
Nov 21, 2024
Oct 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing opened conversation by sending an intent.
1Qualcomm
8Mdm9206 Firmware
Mdm9607 FirmwareMdm9650 Firmware+5 more
Nov 21, 2024
Oct 23, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/S...Show more
Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SDA660.Show less
1Tp Link
1Tl Sc3130 Firmware
Nov 21, 2024
Oct 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI.
1Sv3c
1H.264 Poe Ip Camera Firmware
Nov 21, 2024
Oct 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireles...Show more
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireless network, and local area network information.Show less
1Sv3c
1H.264 Poe Ip Camera Firmware
Nov 21, 2024
Oct 19, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set wi...Show more
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set within the camera. This information can then be used to gain access to the web interface.Show less
1Moxa
1Thingspro
Nov 21, 2024
Oct 19, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
1Dell
1Emc Secure Remote Services
Nov 21, 2024
Oct 18, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens whic...Show more
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the application and subsequent attacks.Show less
1Gxlcms
1Gxlcms
Nov 21, 2024
Oct 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations.