CWE-200
10,497 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,497)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 befo...Show more |
1Ibm 2Platform Symphony Spectrum SymphonyNov 21, 2024 Aug 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information...Show more |
2Netapp Openbsd6Cloud Backup Cn1610 FirmwareData Ontap Edge+3 moreDec 18, 2025 Aug 28, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that t...Show more |
2Openstack Redhat2Cinder OpenstackNov 21, 2024 Aug 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes...Show more |
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenti...Show more |
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi. |
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history. |
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi. |
1Joomanager Project 1Joomanager Nov 21, 2024 Aug 26, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=...Show more |
1Seasofsolutions 1Ip Camera Firmware Nov 21, 2024 Aug 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive information from the device. |
1Seasofsolutions 1Ip Camera Firmware Nov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive information about the network configuration like the network SSID and...Show more |
1Ibm 1Websphere Application Server Nov 21, 2024 Aug 24, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorrect transport being used when Liberty is configured to use Java Authentication SPI for Containers (J...Show more |
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent. |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxNov 21, 2024 Aug 22, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values usi...Show more |
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" co...Show more |
An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with accessibility permissions and the ability to read SMS messages, then the Forg...Show more |
1Geutebrueck 1Re Porter 16 Firmware Nov 21, 2024 Aug 21, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP port 12003. |
2Debian Dropbear Ssh Project2Debian Linux Dropbear SshNov 21, 2024 Aug 21, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a simil...Show more |
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage. |
2Libvirt Redhat10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreNov 21, 2024 Aug 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing. |