CWE-200
10,527 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,527)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dataiku 1Data Science Studio Nov 21, 2024 May 28, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility. |
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 May 28, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex. |
1Werewolf Online Project 1Werewolf Online Nov 21, 2024 May 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output. |
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via spec...Show more |
1Trendmicro 4Antivirus+ Internet SecurityMaximum Security+1 moreJun 17, 2026 May 25, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within p...Show more |
1Ibm 1Storwize Unified V7000 Software Nov 21, 2024 May 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. IBM X-Force ID: 140398. |
2Canonical Haproxy2Haproxy Ubuntu LinuxNov 21, 2024 May 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, rel...Show more |
IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547. |
An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL. |
1Ibm 1Tivoli Application Dependency Discovery Manager Nov 21, 2024 May 24, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in w...Show more |
1Ibm 1Tivoli Application Dependency Discovery Manager Nov 21, 2024 May 24, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct requ...Show more |
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. |
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its sugge...Show more |
An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission. |
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file...Show more |
Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. |
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an att...Show more |
1Ibm 8San Volume Controller Firmware Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 moreNov 21, 2024 May 17, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more |
1Ibm 8San Volume Controller Firmware Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 moreNov 21, 2024 May 17, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more |