CWE-200
10,499 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,499)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from...Show more |
1Microsoft 3Windows Calendar Windows MailWindows PeopleJun 17, 2026 Jul 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information Disclosure Vulnerability." This affects Mail, Calendar, and People in Windows 8.1 App S...Show more |
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from...Show more |
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from...Show more |
1Intel 34Atom C XeonXeon Bronze 3104+31 moreNov 21, 2024 Jul 10, 2018 N/A· v4 7.6 HIGH· v3 4.6 MEDIUM· v2 Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical...Show more |
1Intel 17Core I3 Core I5Core I7+14 moreNov 21, 2024 Jul 10, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical access. |
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories. |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreNov 21, 2024 Jul 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026. |
1Apache 1Directory Ldap Api Nov 21, 2024 Jul 10, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been...Show more |
1Adobe 2Acrobat Dc Acrobat Reader DcNov 21, 2024 Jul 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclo...Show more |
1Adobe 2Acrobat Dc Acrobat Reader DcNov 21, 2024 Jul 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Memory Corruption vulnerability. Successful exploitation could lead to information disclosur...Show more |
IBM API Connect 2018.1.0.0, 2018.2.1, 2018.2.2, 2018.2.3, and 2018.2.4 contains a vulnerability that could allow an authenticated user to obtain sensitive information. IBM X-Force ID: 142657. |
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variable...Show more |
1Thetrackr 1Trackr Bravo Firmware Nov 21, 2024 Jul 6, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Unauthenticated access to the cloud-based service maintained by TrackR Bravo is allowed for querying or sending GPS data for any Trackr device by using the tracker ID number which can be discovered as described in CVE-20...Show more |
The Trackr device ID is constructed of a manufacturer identifier of four zeroes followed by the BLE MAC address in reverse. The MAC address can be obtained by being in close proximity to the Bluetooth device, effectively...Show more |
The TrackR Bravo mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file. Updated apps, version 5.1.6 for iOS and 2.2.5 for Android, have been released by the vendor...Show more |
Lack of copy_from_user and information leak in function "msm_ois_subdev_do_ioctl, file msm_ois.c can lead to a camera crash in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Lin...Show more |
1Qualcomm 27Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+24 moreJun 17, 2026 Jul 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Touch Pal application can collect user behavior data without awareness by the user in Snapdragon Mobile and Snapdragon Wear. |
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreNov 21, 2024 Jul 6, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Multiple IBM Rational products could disclose sensitive information by an attacker that intercepts vulnerable requests. IBM X-Force ID: 131758. |