← Back
CWE-200

10,499 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,499)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Teamviewer
1Teamviewer
Nov 21, 2024
Jul 17, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] and "[00 00 00]" delimiters, which might make it easier for attackers to obtain sensitive information...Show more
TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] and "[00 00 00]" delimiters, which might make it easier for attackers to obtain sensitive information by leveraging an unattended workstation on which TeamViewer has disconnected but remains running.Show less
2Debian
Git Annex Project
2Debian Linux
Git Annex
Nov 21, 2024
Jul 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.
2Debian
Git Annex Project
2Debian Linux
Git Annex
Nov 21, 2024
Jul 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could b...Show more
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git-annexShow less
1Cisco
1Application Policy Infrastructure Controller Enterprise Module
Nov 21, 2024
Jul 16, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient security res...Show more
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient security restrictions imposed by the affected software. An attacker could exploit this vulnerability by accessing unprotected log files. A successful exploit could allow the attacker to access sensitive log files, which may include system credentials, on the affected device. Cisco Bug IDs: CSCvi22400.Show less
1Ibm
1Lotus Notes
Nov 21, 2024
Jul 16, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communicat...Show more
The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communication mechanism for password transmission between Windows and Notes. IBM X-Force ID: 82531.Show less
1Ibm
1Network Operating System
Nov 21, 2024
Jul 13, 2018
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames wi...Show more
The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames with unknown MAC addresses out on all interfaces on the same VLAN, which might allow remote attackers to obtain sensitive information in opportunistic circumstances by eavesdropping on the broadcast domain. IBM X-Force ID: 83166.Show less
1Accellion
1Ftp Server
Nov 21, 2024
Jul 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
1Zohocorp
1Manageengine Applications Manager
Nov 21, 2024
Jul 13, 2018
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system fi...Show more
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.Show less
1Nutspace
1Nut Mobile
Nov 21, 2024
Jul 13, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to ga...Show more
The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account.Show less
1Nutspace
1Nut Mobile
Nov 21, 2024
Jul 13, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.
1Kkmcn
1Itrackeasy
Nov 21, 2024
Jul 13, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.
1Ieasytec
1Itrackeasy
Nov 21, 2024
Jul 13, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Jul 13, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Securi...Show more
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 127341.Show less
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Jul 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the U...Show more
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126860.Show less
1Komoot
1Komoot
Nov 21, 2024
Jul 12, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to...Show more
The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
2Apache
Mozilla
2Firefox
Spark
Jun 17, 2026
Jul 12, 2018
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing th...Show more
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.Show less
1Apache
1Spark
Nov 21, 2024
Jul 12, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application...Show more
In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.Show less
1Cloudfoundry
2Cf Release
Java Buildpack
Nov 21, 2024
Jul 11, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications...Show more
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through the Java Buildpack detection script, and allow the serving of static content from within the deployed artifact. The default Apache Tomcat configuration in the affected java buildpack versions for some basic web application archive (WAR) packaged applications are vulnerable to this issue.Show less
1Ibm
1Inotes
Nov 21, 2024
Jul 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive information via a crafted e-mail message. IBM X-Force ID: 83371.
1Microsoft
1Edge
Jun 17, 2026
Jul 11, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from...Show more
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8297, CVE-2018-8324.Show less