CWE-200
10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,521)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430. |
1Express Restify Mongoose Project 1Express Restify Mongoose Nov 21, 2024 May 31, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /...Show more |
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same netwo...Show more |
A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a listening peer and get it to reveal internal memory. |
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the...Show more |
1Ruckuswireless 4Scg 200 Firmware Sz 100 FirmwareSz 300 Firmware+1 moreNov 21, 2024 May 31, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain sensitive information...Show more |
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information. |
The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file. |
The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file. |
1Node Tkinter Project 1Node Tkinter Nov 21, 2024 May 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 May 29, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer h...Show more |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 May 29, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 136471. |
1Dataiku 1Data Science Studio Nov 21, 2024 May 28, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility. |
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 May 28, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex. |
1Werewolf Online Project 1Werewolf Online Nov 21, 2024 May 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output. |
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via spec...Show more |
1Trendmicro 4Antivirus+ Internet SecurityMaximum Security+1 moreJun 17, 2026 May 25, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within p...Show more |