← Back
CWE-200

10,518 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,518)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Lon Al00b Firmware
Nov 21, 2024
Mar 9, 2018
N/A· v4
3.5 LOW· v3
2.9 LOW· v2
NFC (Near Field Communication) module in Huawei mobile phones with software LON-AL00BC00 has an information leak vulnerability. The attacker has to trick a user to do some specific operations and then craft the NFC messa...Show more
NFC (Near Field Communication) module in Huawei mobile phones with software LON-AL00BC00 has an information leak vulnerability. The attacker has to trick a user to do some specific operations and then craft the NFC message to exploit this vulnerability. Successful exploit will cause some information leak.Show less
1Ibm
3Application Performance Management
Cloud Apm Data CollectorMonitoring
Nov 21, 2024
Mar 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensitive personal data to the staff who can access to the database of this product. IBM X-Force ID: 138210...Show more
IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensitive personal data to the staff who can access to the database of this product. IBM X-Force ID: 138210.Show less
1Ibm
1Qradar Pulse
Nov 21, 2024
Mar 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Pulse for QRadar 1.0.0 - 1.0.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 133123.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Mar 8, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An atta...Show more
An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use the obtained kernel pointer to discover the location of kernel code and data and bypass kernel security protections such as KASLR.Show less
1Cisco
1Secure Access Control Server Solution Engine
Nov 21, 2024
Mar 8, 2018
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected sy...Show more
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file. Cisco Bug IDs: CSCve70616.Show less
1Cisco
1Secure Access Control Server Solution Engine
Nov 21, 2024
Mar 8, 2018
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected sy...Show more
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file. Cisco Bug IDs: CSCve70595.Show less
1Microfocus
1Sentinel
Jun 17, 2026
Mar 7, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes...Show more
In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to re-authenticate. If another user is passing by and decides to login, their credentials are accepted. While The user does not inherit any of the other users privileges, they are able to view the previous screen. In this case it is possible that the user can see another users events or configuration information for whatever view is currently showing.Show less
1Zblogcn
1Z Blogphp
Jun 17, 2026
Mar 6, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vulnerability
1Belden
134Hirschmann M1 8mm Sc
Hirschmann M1 8sfpHirschmann M1 8sm Sc+131 more
Jun 17, 2026
Mar 6, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through...Show more
An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user.Show less
1Citrix
2Netscaler Application Delivery Controller Firmware
Netscaler Gateway Firmware
Jun 17, 2026
Mar 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.
2Google
Nvidia
2Android
Shield Tv Firmware
Nov 21, 2024
Mar 6, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that i...Show more
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to information disclosure.This issue is rated as moderate.Show less
2Google
Nvidia
2Android
Shield Tv Firmware
Nov 21, 2024
Mar 6, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.
1Google
1Android
Nov 21, 2024
Mar 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NVIDIA driver contains a possible out-of-bounds read vulnerability due to a leak which may lead to information disclosure. This issue is rated as moderate. Android: A-63851980.
1Huawei
1Mate 9 Firmware
Nov 21, 2024
Mar 5, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Succe...Show more
Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Successful exploitation may cause sensitive information leak.Show less
1Huawei
2Enjoy 5s Firmware
Y6 Pro Firmware
Nov 21, 2024
Mar 5, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter validation. An attacker tr...Show more
Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information leak vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious application on the smart phone and the application can read some sensitive information in kernel memory which may cause sensitive information leak.Show less
1Huawei
2Mate 9 Firmware
Mate 9 Pro Firmware
Nov 21, 2024
Mar 5, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions before LON-AL00B 8.0.0.334(C00) have a information leak vulnerability in the date service proxy implement...Show more
Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions before LON-AL00B 8.0.0.334(C00) have a information leak vulnerability in the date service proxy implementation. An attacker may trick a user into installing a malicious application and application can exploit the vulnerability to get kernel date which may cause sensitive information leak.Show less
1Qnap
1Qfinder Pro
Nov 21, 2024
Mar 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device.
1Testlink
1Testlink
Jun 17, 2026
Mar 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.
1Couchcms
1Couch
Jun 17, 2026
Mar 4, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.
1Babyphonemobile
1Wifi Baby Monitor
Jun 17, 2026
Mar 4, 2018
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests to TCP ports 8258 and 8257.