← Back
CWE-200

10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,521)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Mq
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data in cleartext outside...Show more
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data in cleartext outside the protected payload. IBM X-Force ID: 103482.Show less
1Ibm
1Security Siteprotector System
Nov 21, 2024
Apr 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unspecified commands and obtain sensitive information via unknown vectors....Show more
IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unspecified commands and obtain sensitive information via unknown vectors. IBM X-Force ID: 100927.Show less
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto c...Show more
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto configuration for external accounts.Show less
1Icmsdev
1Icms
Jun 17, 2026
Apr 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.
2Debian
Zabbix
2Debian Linux
Zabbix
Nov 21, 2024
Apr 9, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbi...Show more
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.Show less
1Gxlcms
1Gxlcms Qy
Jun 17, 2026
Apr 8, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a query string within a Home-Hits request, as demonstrated hy sid=user,p...Show more
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a query string within a Home-Hits request, as demonstrated hy sid=user,password%20from%20mysql.user%23.Show less
1Etherpad
1Etherpad
Jun 17, 2026
Apr 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
1Oleumtech
2Ad1 Firmware
Ft1 Firmware
Nov 21, 2024
Apr 6, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or spoof devices by reading cleartext protocol data.
1Moxa
1Mxview
Jun 17, 2026
Apr 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.
1Google
1Android
Nov 21, 2024
Apr 5, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.
1Apache
1Hive
Nov 21, 2024
Apr 5, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the mach...Show more
In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.Show less
1Jenkins
1Reverse Proxy Auth
Nov 21, 2024
Apr 5, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list o...Show more
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.Show less
1Jenkins
1Copy To Slave
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jobs to read arbitrary...Show more
An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jobs to read arbitrary files from the Jenkins master file system.Show less
1Perforce
1Perforce
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwo...Show more
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwords configured in jobs to obtain themShow less
1Jenkins
1Perforce
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perf...Show more
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perforce passwords and decrypt them.Show less
1Jenkins
1Github Pull Request Builder
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub c...Show more
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.Show less
1Jenkins
1Github Pull Request Builder
Nov 21, 2024
Apr 5, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub c...Show more
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.Show less
2Redhat
Theforeman
2Foreman
Satellite
Nov 21, 2024
Apr 4, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
1Zldnn
1Dnnarticle
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.
1Yubico
1Yubico Pam
Jun 17, 2026
Apr 4, 2018
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of...Show more
In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).Show less