CWE-200
10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,521)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons. |
Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in information disclosure. |
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which...Show more |
1Rockwellautomation 1Micrologix 1400 B Firmware Nov 21, 2024 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new progra...Show more |
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodefabric Project 1Nodefabric Nov 21, 2024 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 `nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Node Fabric Project 1Node Fabric Nov 21, 2024 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 `node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Nodesqlite Project 1Nodesqlite Nov 21, 2024 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 `nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Node Sqlite Project 1Node Sqlite Nov 21, 2024 Jun 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 `node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
2Nodejs Sync Exec Project2Node.js Sync ExecNov 21, 2024 Jun 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp director...Show more |
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack....Show more |
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored. |
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user,...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Jun 1, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include...Show more |
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016...Show more |