CWE-200
10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,521)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Coffescript Project 1Coffescript Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
1Coffescript Project 1Coffescript Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
1Coffescript Project 1Coffescript Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
1Cofeescript Project 1Cofeescript Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. |
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is known to record and track user information. The module tracks the following information. Source IP proc...Show more |
1Cross Env.js Project 1Cross Env.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Shadowsock Project 1Shadowsock Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Http Proxy.js Project 1Http Proxy.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Noderequest Project 1Noderequest Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodemailer.js Project 1Nodemailer.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodemailer Js Project 1Nodemailer Js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodeffmpeg Project 1Nodeffmpeg Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |