← Back
CWE-200

10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,521)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Api Connect
Nov 21, 2024
May 31, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM API Connect 5.0.0.0 through 5.0.8.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 142430.
1Express Restify Mongoose Project
1Express Restify Mongoose
Nov 21, 2024
May 31, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /...Show more
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the field being set to private. This can be used for other private data if the malicious user knew what was set as private for specific routes.Show less
1Airbrake
1Airbrake
Nov 21, 2024
May 31, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same netwo...Show more
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same network as a regular user and intercept all the secret keys the user is sending. This goes against common best practice, which is to use HTTPS.Show less
1Webtorrent
1Bittorrent Dht
Nov 21, 2024
May 31, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a listening peer and get it to reveal internal memory.
1Hapijs
1Hapi
Nov 21, 2024
May 31, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the...Show more
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the connection has CORS enabled but one route has it off, and the route is not GET, the OPTIONS prefetch request will return the default CORS headers and then the actual request will go through and return no CORS headers. This defeats the purpose of turning CORS on the route.Show less
1Ruckuswireless
4Scg 200 Firmware
Sz 100 FirmwareSz 300 Firmware+1 more
Nov 21, 2024
May 31, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain sensitive information...Show more
Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain sensitive information or modify data.Show less
1Mahara
1Mahara
Nov 21, 2024
May 30, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.
1Libmobi Project
1Libmobi
Nov 21, 2024
May 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.
1Libmobi Project
1Libmobi
Nov 21, 2024
May 30, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.
1Node Tkinter Project
1Node Tkinter
Nov 21, 2024
May 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Tkinter Package
1Tkinter
Nov 21, 2024
May 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Mysqljs Project
1Mysqljs
Nov 21, 2024
May 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
1Ibm
1Security Guardium Big Data Intelligence
Nov 21, 2024
May 29, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer h...Show more
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 137767.Show less
1Ibm
1Security Guardium Big Data Intelligence
Nov 21, 2024
May 29, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 136471.
1Dataiku
1Data Science Studio
Nov 21, 2024
May 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
1Myscada
1Mypro
Nov 21, 2024
May 28, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
May 28, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
1Werewolf Online Project
1Werewolf Online
Nov 21, 2024
May 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
1Fortinet
1Fortios
Nov 21, 2024
May 25, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via spec...Show more
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.Show less
1Trendmicro
4Antivirus+
Internet SecurityMaximum Security+1 more
Jun 17, 2026
May 25, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within p...Show more
An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less