CWE-200
10,498 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,498)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
LICA miniCMTS E8K(u/i/...) devices allow remote attackers to obtain sensitive information via a direct POST request for the inc/user.ini file, leading to discovery of a password hash. |
1Echelon 3I.lon 100 Firmware Smartserver 1 FirmwareSmartserver 2 FirmwareJun 2, 2026 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 6.4 MEDIUM· v2 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuratio...Show more |
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an information leak. |
1Netgear 2Dgn2200 Firmware Dgnd3700 FirmwareNov 21, 2024 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without a...Show more |
There are few web pages associated with the genie app on the Netgear WNDR4500 running firmware version V1.0.1.40_1.0.6877. Genie app adds some capabilities over the Web GUI and can be accessed even when you are away from...Show more |
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about...Show more |
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboar...Show more |
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted...Show more |
October CMS version prior to Build 437 contains a Local File Inclusion vulnerability in modules/system/traits/ViewMaker.php#244 (makeFileContents function) that can result in Sensitive information disclosure and remote c...Show more |
1Ibm 1Sterling B2b Integrator Nov 21, 2024 Jul 20, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 145180. |
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow a local user with administrator privileges to obtain user passwords found in debugging messages. IBM X-Force ID: 142968. |
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote authenticated attacker to obtain sensitive information displayed in the URL that could lead to further attacks against the system. IBM X-Force ID: 140688...Show more |
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain sensitive information. IBM X-Force ID: 138434. |
1Ibm 1Sterling B2b Integrator Nov 21, 2024 Jul 20, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name information using specially crafted HTTP requests. IBM X-Force ID: 133180. |
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwords in browsers that could be used by a local attacker to obtain sensitive information. IBM X-Force...Show more |
2Canonical Gnome2Evolution Ubuntu LinuxNov 21, 2024 Jul 20, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will n...Show more |
1Ibm 2Rational Rhapsody Design Manager Rational Software Architect Design ManagerNov 21, 2024 Jul 19, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Rational Rhapsody Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 and IBM Rational Software Architect Design Manager 5.0 through 5.0.2 and 6.0 through 6.0.1 could reveal technical error messages to allow an ad...Show more |
1Ibm 1Qradar Security Information And Event Manager Nov 21, 2024 Jul 17, 2018 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164. |
1Trivum 1C4 Professional Firmware Nov 21, 2024 Jul 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18 allows unauthorized remote attackers to obtain sensitive information via the "/xml/menu/getObjectEditor....Show more |
TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] and "[00 00 00]" delimiters, which might make it easier for attackers to obtain sensitive information...Show more |