CWE-200
10,498 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,498)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated per...Show more |
1Netcommwireless 1Nwl 25 Firmware Nov 21, 2024 Aug 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without authentication. |
1Netcommwireless 1Nwl 25 Firmware Nov 21, 2024 Aug 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating the user. |
Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage. |
1Hitachi 6Command Suite Compute Systems ManagerDevice Manager+3 moreNov 21, 2024 Aug 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of messaging that may allow for information exposure via a crafted message. |
4Canonical DebianPostgresql+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 9, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" co...Show more |
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Aug 7, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call. |
2Netapp Php2Php Storage Automation StoreNov 21, 2024 Aug 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This...Show more |
jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically created list of users based on the changelogs, like authors of SCM cha...Show more |
1Hp 1Network Function Virtualization Director Jun 17, 2026 Aug 6, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3. |
1Hp 1Centralview Fraud Risk Management Jun 17, 2026 Aug 6, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version. |
ArubaOS, all versions prior to 6.3.1.25, 6.4 prior to 6.4.4.16, 6.5.x prior to 6.5.1.9, 6.5.2, 6.5.3 prior to 6.5.3.3, 6.5.4 prior to 6.5.4.2, 8.x prior to 8.1.0.4 FIPS and non-FIPS versions of software are both affected...Show more |
1Ibm 8Maximo Asset Management Maximo For AviationMaximo For Life Sciences+5 moreNov 21, 2024 Aug 6, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Maximo Asset Management 7.6 through 7.6.3 could allow an authenticated user to obtain sensitive information from the WhoAmI API. IBM X-Force ID: 142290. |
1Ibm 1Security Identity Governance And Intelligence Nov 21, 2024 Aug 6, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400. |
1Ibm 1Security Identity Governance And Intelligence Nov 21, 2024 Aug 6, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 127396. |
Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for the /webapp.py URI. |
/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter. |
An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the...Show more |
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins...Show more |