CWE-200
10,498 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,498)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Anchore 1Container Image Scanner Nov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system...Show more |
An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows attackers with file system access to the Jenkins master to obtain the API k...Show more |
1Jenkins 1Maven Artifact Choicelistprovider (nexus) Nov 21, 2024 Aug 1, 2018 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceLis...Show more |
An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins. |
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can...Show more |
1Foxitsoftware 2Foxit Reader PhantompdfNov 21, 2024 Jul 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visi...Show more |
1Foxitsoftware 2Foxit Reader PhantompdfNov 21, 2024 Jul 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visi...Show more |
1Foxitsoftware 2Foxit Reader PhantompdfNov 21, 2024 Jul 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visi...Show more |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Jul 31, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose configuration information such as partition and agent names via URI par...Show more |
3Debian OpenstackRedhat3Debian Linux KeystoneOpenstackNov 21, 2024 Jul 31, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated...Show more |
The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index.php?s=Admin-Tpl-ADD-id request, related to Lib/Common/Admin/function.p...Show more |
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result...Show more |
2Debian X.org2Debian Linux X ServerAug 29, 2025 Jul 27, 2018 N/A· v4 7.0 HIGH· v3 1.9 LOW· v2 It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since mos...Show more |
2Fedoraproject Redhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+3 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password ha...Show more |
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive informatio...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private...Show more |
1Redhat 2Jboss Enterprise Application Platform KeycloakNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jul 26, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information...Show more |
3Debian RedhatSamba6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.1 HIGH· v3 4.8 MEDIUM· v2 An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a...Show more |
3Canonical DebianGnupg3Debian Linux LibgcryptUbuntu LinuxNov 21, 2024 Jul 26, 2018 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is...Show more |