← Back
CWE-200

10,499 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,499)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Sitescope
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.
1Hp
1Sitescope
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.
1Hp
1Cloud Optimizer
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Remote Disclosure of Information vulnerability in HPE Cloud Optimizer version v3.0x was found.
1Hp
1Network Automation
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
1Hp
1Nonstop Server Software
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Remote Disclosure of Information vulnerability in HPE NonStop Servers using SSH Service version L series: T0801L02 through T0801L02^ABX; J and H series: T0801H01 through T0801H01^ACA was found.
1Hp
1Business Process Monitor
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Remote Unauthorized Access to Data vulnerability in HPE Business Process Monitor version v09.2x, v09.30 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Remote Unauthenticated Disclosure of Information vulnerability in HPE Intelligent Management Center (IMC) SOM version v7.3 (E0501) was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
A Local Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) version PLAT 7.2 E0403P06 was found.
1Hp
1Nonstop Server Software
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found.
1Hp
1Matrix Operating Environment
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
A remote arbitrary file download and disclosure of information vulnerability in HPE Intelligent Management Center (iMC) Service Operation Management (SOM) version IMC SOM 7.3 E0501 was found.
1Hp
4Integrated Lights Out 2 Firmware
Integrated Lights Out 3 FirmwareIntegrated Lights Out 4 Firmware+1 more
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A remote disclosure of information vulnerability in Moonshot Remote Console Administrator Prior to 2.50, iLO4 prior to v2.53, iLO3 prior to v1.89 and iLO2 prior to v2.30 was found.
1Hp
1Matrix Operating Environment
Nov 21, 2024
Feb 15, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A remote information disclosure vulnerability in HPE Matrix Operating Environment version 7.6 was found.
1Hp
1Intelligent Management Center
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Remote Disclosure of Information vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMC PLAT 7.3 E0504 or subsequent version.
1Hp
1Version Control Repository Manager
Nov 21, 2024
Feb 15, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.
1Steelcase
1Roomwizard Firmware
Jun 17, 2026
Feb 15, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
RoomWizard before 4.4.x allows remote attackers to obtain potentially sensitive information about IP addresses via /getGroupTimeLineJSON.action.
1Smiths Medical
1Medfusion 4000 Wireless Syringe Infusion Pump
Nov 21, 2024
Feb 15, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are access...Show more
A Password in Configuration File issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump stores some passwords in the configuration file, which are accessible if the pump is configured to allow external communications.Show less
1Microsoft
2Windows 7
Windows Server 2008
Nov 21, 2024
Feb 15, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows E...Show more
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0760, and CVE-2018-0761.Show less
1Microsoft
2Windows 10
Windows Server 2016
Nov 21, 2024
Feb 15, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The Windows kernel in Windows 10 version 1709 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Kernel Information Disclosure Vulnerabi...Show more
The Windows kernel in Windows 10 version 1709 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0742, CVE-2018-0756, CVE-2018-0809 and CVE-2018-0820.Show less
1Microsoft
1Edge
Nov 21, 2024
Feb 15, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge in Microsoft Windows 10 1703 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0763.