← Back
CWE-200

10,499 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,499)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Content Security Management Appliance
Email Security Appliance Firmware
Nov 21, 2024
Feb 8, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by m...Show more
A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of authenticated user accounts. An attacker could exploit this vulnerability by modifying browser strings to see messages submitted by other users to the spam quarantine within their company. Cisco Bug IDs: CSCvg39759, CSCvg42295.Show less
1Cisco
1Mobility Services Engine
Nov 21, 2024
Feb 8, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Po...Show more
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS server component returns different authentication failure messages based on the validity of usernames. An attacker could use these messages to determine whether a valid subscriber username has been identified. The attacker could use this information in subsequent attacks against the system. Cisco Bug IDs: CSCvg47830.Show less
1Cisco
2Rv132w Firmware
Rv134w Firmware
Nov 21, 2024
Feb 8, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an af...Show more
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examining the HTTP response to the request. A successful exploit could allow the attacker to view configuration parameters, including the administrator password, for the affected device. Cisco Bug IDs: CSCvg92739, CSCvh60172.Show less
1Ibm
1Websphere Mq
Nov 21, 2024
Feb 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.
1Ibm
1Api Connect
Nov 21, 2024
Feb 7, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.
1Marked 2 Project
1Marked 2
Jun 17, 2026
Feb 7, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaS...Show more
Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.Show less
1Kde
1Plasma Workspace
Jun 17, 2026
Feb 7, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the...Show more
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.Show less
1Web2py
1Web2py
Nov 21, 2024
Feb 6, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary cod...Show more
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.Show less
1Sandstorm
1Sandstorm
Nov 21, 2024
Feb 6, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n) charact...Show more
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n) characters in a directory name.Show less
1Apache
1Cloudstack
Nov 21, 2024
Feb 6, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
1Jlike Project
1Jlike
Jun 17, 2026
Feb 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
1Freebsd
1Freebsd
Nov 21, 2024
Feb 5, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p1, allows remote atta...Show more
The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p1, allows remote attackers to execute arbitrary commands via a crafted patch file, because a '!' character can be passed to the ed program.Show less
2Canonical
Djangoproject
2Django
Ubuntu Linux
Jun 17, 2026
Feb 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allow...Show more
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.Show less
2Debian
Django Anymail Project
2Debian Linux
Django Anymail
Jun 17, 2026
Feb 3, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
1Ibm
1Tririga Application Platform
Nov 21, 2024
Feb 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors related to granting unauthenticated access to Document Manager. IBM X-Force ID: 111486.
1Mantisbt
1Mantisbt
Jun 17, 2026
Feb 2, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.p...Show more
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path via an invalid filter parameter, related to a filter_ensure_valid_filter call in current_user_api.php.Show less
1Pivotal Software
4Cloud Foundry Cf Deployment
Cloud Foundry Cf ReleaseCloud Foundry Uaa+1 more
Nov 21, 2024
Feb 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45...Show more
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the SessionID is logged in audit event logs. An attacker can use the SessionID to impersonate a logged-in user.Show less
1Evergreen Ils
1Evergreen
Nov 21, 2024
Feb 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-i...Show more
Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restriction and obtain sensitive information about org unit settings by leveraging failure of open-ils.actor.ou_setting.ancestor_default to enforce view_perm when no auth token is provided.Show less
1Evergreen Ils
1Evergreen
Nov 21, 2024
Feb 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings history information by leveraging listing of open-ils.pcrud as a controller in the IDL.
1Evergreen Ils
1Evergreen
Nov 21, 2024
Feb 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retriev...Show more
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.Show less