CWE-200
10,527 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,527)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 16Msm8909w Firmware Sd 205 FirmwareSd 210 Firmware+13 moreNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, and S...Show more |
1Qualcomm 27Mdm9206 Firmware Mdm9650 FirmwareMsm8909w Firmware+24 moreNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430,...Show more |
1Qualcomm 37Fsm9055 Firmware Ipq4019 FirmwareMdm9206 Firmware+34 moreNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, M...Show more |
1Qualcomm 34Mdm9206 Firmware Mdm9607 FirmwareMdm9615 Firmware+31 moreNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD...Show more |
1Qualcomm 28Mdm9206 Firmware Mdm9607 FirmwareMdm9640 Firmware+25 moreNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450...Show more |
1Qualcomm 2Sd 400 Firmware Sd 800 FirmwareNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there could be leakage of protected contents if HLOS doesn't request for security restoration for OCMEM xPU's. |
1Qualcomm 2Sd 400 Firmware Sd 800 FirmwareNov 21, 2024 Apr 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writing the Full Disk Encryption key to crypto engine, information leak could occur. |
An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies per contact due to tracking the contact by their auto-incremented ID. Thus, a third party can manipul...Show more |
1Tibco 3Jasperreports Server JaspersoftJaspersoft Reporting And AnalyticsJun 17, 2026 Apr 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TI...Show more |
The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisitedSites command. |
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.php?a=%0a_POST_SERVICES...Show more |
An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of ag...Show more |
MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext. |
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Apr 13, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /...Show more |
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the administrative password. |
3Clusterlabs DebianRedhat3Debian Linux Enterprise Linux Server EusPacemaker Command Line InterfaceNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensi...Show more |
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. |
2Kaazing Tenefit2Kaazing Gateway Kaazing Websocket GatewayNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotf...Show more |
1Tenefit 1Kaazing Websocket Gateway Nov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors relat...Show more |