← Back
CWE-200

10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,521)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Coffescript Project
1Coffescript
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Coffescript Project
1Coffescript
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Jquey Project
1Jquey
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Coffescript Project
1Coffescript
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Cofeescript Project
1Cofeescript
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
1Botbait Project
1Botbait
Nov 21, 2024
Jun 7, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user information. The module tracks the following information. Source IP proc...Show more
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user information. The module tracks the following information. Source IP process.versions process.platform How the module was invoked (test, require, pre-install)Show less
1Cross Env.js Project
1Cross Env.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodesass Project
1Nodesass
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Smb Project
1Smb
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Shadowsock Project
1Shadowsock
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Mongose Project
1Mongose
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Proxy.js Project
1Proxy.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Http Proxy.js Project
1Http Proxy.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Crossenv Project
1Crossenv
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Noderequest Project
1Noderequest
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodemailer.js Project
1Nodemailer.js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodemailer Js Project
1Nodemailer Js
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodecaffe Project
1Nodecaffe
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodeffmpeg Project
1Nodeffmpeg
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Ffmepg Project
1Ffmepg
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.