← Back
CWE-200

10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,521)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Storm
Nov 21, 2024
Jun 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
1Ibm
1Kitura
Nov 21, 2024
Jun 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in information disclosure.
1Yzmcms
1Yzmcms
Nov 21, 2024
Jun 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which...Show more
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts via a brute-force approach.Show less
1Rockwellautomation
1Micrologix 1400 B Firmware
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new progra...Show more
An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new program being written to the memory module. An attacker can send an unauthenticated packet to trigger this vulnerability.Show less
1Sqlserver Project
1Sqlserver
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodefabric Project
1Nodefabric
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Fabric Js Project
1Fabric Js
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Node Fabric Project
1Node Fabric
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Sqliter Project
1Sqliter
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Sqlite.js Project
1Sqlite.js
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Nodesqlite Project
1Nodesqlite
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Node Sqlite Project
1Node Sqlite
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Jquery.js Project
1Jquery.js
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1D3.js Project
1D3.js
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
2Nodejs
Sync Exec Project
2Node.js
Sync Exec
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp director...Show more
The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.Show less
1Cisco
1Node Jose
Nov 21, 2024
Jun 4, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack....Show more
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.Show less
1Zeit
1Serve
Nov 21, 2024
Jun 1, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.
1Mahara
1Mahara
Nov 21, 2024
Jun 1, 2018
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user,...Show more
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials.Show less
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Jun 17, 2026
Jun 1, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include...Show more
A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic, or other potentially sensitive customer data.Show less
1Artifex
1Ghostscript
Nov 21, 2024
Jun 1, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016...Show more
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.Show less