← Back
CWE-200

10,498 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Urbancode Deploy
Nov 21, 2024
Aug 13, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated per...Show more
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.Show less
1Netcommwireless
1Nwl 25 Firmware
Nov 21, 2024
Aug 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without authentication.
1Netcommwireless
1Nwl 25 Firmware
Nov 21, 2024
Aug 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating the user.
1Microfocus
1Edirectory
Jun 17, 2026
Aug 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.
1Hitachi
6Command Suite
Compute Systems ManagerDevice Manager+3 more
Nov 21, 2024
Aug 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of messaging that may allow for information exposure via a crafted message.
4Canonical
DebianPostgresql+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
Nov 21, 2024
Aug 9, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" co...Show more
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Aug 7, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.
2Debian
Linux
2Debian Linux
Linux Kernel
Jun 17, 2026
Aug 7, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.
2Netapp
Php
2Php
Storage Automation Store
Nov 21, 2024
Aug 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This...Show more
An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This could be abused to find files on paths outside of the allowed directories.Show less
1Jenkins
1Email Extension
Nov 21, 2024
Aug 6, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM cha...Show more
jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM changes since the last successful build. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people who were not involved in whatever project was being built, due to some mapping based on the local-part of email addresses.Show less
1Hp
1Network Function Virtualization Director
Jun 17, 2026
Aug 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.
1Hp
1Centralview Fraud Risk Management
Jun 17, 2026
Aug 6, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.
1Hp
1Arubaos
Nov 21, 2024
Aug 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x prior to 8.1.0.4 FIPS and non-FIPS versions of software are both affected...Show more
ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x prior to 8.1.0.4 FIPS and non-FIPS versions of software are both affected equally is vulnerable to unauthenticated arbitrary file access. An unauthenticated user with network access to an Aruba mobility controller on TCP port 8080 or 8081 may be able to access arbitrary files stored on the mobility controller. Ports 8080 and 8081 are used for captive portal functionality and are listening, by default, on all IP interfaces of the mobility controller, including captive portal interfaces. The attacker could access files which could contain passwords, keys, and other sensitive information that could lead to full system compromise.Show less
1Ibm
8Maximo Asset Management
Maximo For AviationMaximo For Life Sciences+5 more
Nov 21, 2024
Aug 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Aug 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Aug 6, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 127396.
1Harmonicinc
1Nsg 9000
Nov 21, 2024
Aug 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for the /webapp.py URI.
1Matera
1Banco
Nov 21, 2024
Aug 3, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter.
1Jenkins
1Tinfoil Security
Nov 21, 2024
Aug 1, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the...Show more
An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in this plugin's configuration.Show less
1Jenkins
1Kubernetes
Nov 21, 2024
Aug 1, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins...Show more
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.Show less