← Back
CWE-200

10,496 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,496)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
2Asp.net Core
Powershell Core
Jun 17, 2026
Oct 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET C...Show more
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.Show less
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 8, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Oct 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 148422.
1Gitea
1Gitea
Nov 21, 2024
Oct 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notificatio...Show more
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if they have the email set as private. This vulnerability appears to have been fixed in 1.5.1.Show less
1Cisco
1Prime Infrastructure
Nov 21, 2024
Oct 5, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive informati...Show more
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A successful exploit could allow the attacker to view sensitive information.Show less
1Cisco
1Prime Infrastructure
Nov 21, 2024
Oct 5, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive informati...Show more
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. A successful exploit could allow the attacker to view sensitive information.Show less
1Cisco
1Hyperflex Hx Data Platform
Nov 21, 2024
Oct 5, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files....Show more
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.Show less
1Cisco
3Rv110w Firmware
Rv130w FirmwareRv215w Firmware
Nov 21, 2024
Oct 5, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated,...Show more
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to gain access to sensitive configuration information, including user authentication credentials.Show less
1Ibm
1Spectrum Scale
Nov 21, 2024
Oct 5, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373...Show more
IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node. IBM X-Force ID: 147373.Show less
1Wp Db Backup Project
1Wp Db Backup
Nov 21, 2024
Oct 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
1Carestream
1Carestream Vue Ris
Nov 21, 2024
Oct 4, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP...Show more
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical information an attacker could use to initiate a more elaborate attack.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Oct 4, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Oct 4, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive product configuration information from log files. IBM X-Force ID: 144946.
1Apache
1Pony Mail
Nov 21, 2024
Oct 4, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of...Show more
The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, though without disclosing the content itself. As this was primarily used as a caching feature for faster loading times, the caching was disabled by default to prevent this. Users using 0.9 should upgrade to 0.10 to address this issue.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Oct 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Orphaned Upload Files Exposure.
1Entes
1Emg 12 Firmware
Nov 21, 2024
Oct 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary...Show more
Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary code.Show less
1Nvidia
1Geforce Experience
Jun 17, 2026
Oct 2, 2018
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user information may be available to users with system access, which may lead to information disclosure.
1Wpmobilepack
1Wordpress Mobile Pack
Nov 21, 2024
Oct 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obtain sensitive information because the content of a privately published...Show more
The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obtain sensitive information because the content of a privately published post is sent in JSON format.Show less
1Ptc
1Thingworx Platform
Nov 21, 2024
Oct 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.
1Telegram
2Telegram Desktop
Telegram Messenger
Nov 21, 2024
Sep 29, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from...Show more
Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from clients outside of the My Contacts list.Show less