CWE-200
10,518 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,518)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or simi...Show more |
1Ibm 2General Parallel File System Spectrum ScaleNov 21, 2024 Mar 2, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378. |
3Debian DovecotUbuntu3Debian Linux DovecotUbuntuNov 21, 2024 Mar 2, 2018 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vuln...Show more |
In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerabilit...Show more |
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information. |
1Ibm 1Tririga Application Platform Nov 21, 2024 Feb 28, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive information via vectors involving a database query. IBM X-Force ID: 111382. |
2Debian Limesurvey2Debian Linux LimesurveyJun 17, 2026 Feb 28, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file. |
1Synology 1Surveillance Station Nov 21, 2024 Feb 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensiti...Show more |
An issue was discovered on Wireless IP Camera 360 devices. Attackers can read recordings by navigating to /mnt/idea0 or /mnt/idea1 on the SD memory card. |
2Microsoft Tivo5Safedisc Windows 7Windows 8+2 moreJun 17, 2026 Feb 26, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCT...Show more |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 Feb 26, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 136818. |
When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode l...Show more |
1Netapp 2Oncommand Api Services Service Level ManagerNov 21, 2024 Feb 23, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected pas...Show more |
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode. |
1Christianwebministries 1Proclaim Jun 17, 2026 Feb 22, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. |
1Ibm 1Financial Transaction Manager Nov 21, 2024 Feb 22, 2018 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 1383...Show more |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Feb 21, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072. |
1Ibm 1Security Privileged Identity Manager Nov 21, 2024 Feb 21, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071. |
1Ibm 1Security Identity Manager Virtual Appliance Nov 21, 2024 Feb 21, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cook...Show more |
1Ibm 1Tririga Application Platform Nov 21, 2024 Feb 21, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force I...Show more |