← Back
CWE-200

10,498 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Jan 4, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header...Show more
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 133636.Show less
1Microsoft
2Chakracore
Edge
Nov 21, 2024
Jan 4, 2018
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information D...Show more
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0780.Show less
1Microsoft
1Edge
Nov 21, 2024
Jan 4, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the Microsoft Edge PDF Reader hand...Show more
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the Microsoft Edge PDF Reader handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability".Show less
2Arm
Intel
209Atom C
Atom EAtom X3+206 more
May 28, 2026
Jan 4, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data c...Show more
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.Show less
1Linaro
1Op Tee
Nov 21, 2024
Jan 2, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
1Linaro
1Op Tee
Nov 21, 2024
Jan 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
1Flir
2Brickstream 2300 2d Firmware
Brickstream 2300 3d Firmware
Nov 21, 2024
Jan 1, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and AVI_USER_PASSWORD fields via a direct request.
1Dkd
1Direct Mail
May 13, 2026
Dec 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.
1Ordermanagementscript
1Professional Service Script
May 13, 2026
Dec 27, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
1Dolibarr
1Dolibarr Erp/crm
May 13, 2026
Dec 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
2Debian
Linux
2Debian Linux
Linux Kernel
May 13, 2026
Dec 27, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address...Show more
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."Show less
1Ibm
1Websphere Portal
May 13, 2026
Dec 27, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
Dec 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. I...Show more
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
Dec 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. I...Show more
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 13, 2026
Dec 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. I...Show more
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.Show less
1Apple
2Icloud
Itunes
May 13, 2026
Dec 25, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attack...Show more
An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attackers to track users by leveraging mishandling of client certificates.Show less
1Huawei
1Hg8245h Firmware
May 13, 2026
Dec 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect product. Due to improper verification of the privilege, successful exp...Show more
Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect product. Due to improper verification of the privilege, successful exploitation may cause information leak.Show less
1Huawei
1Fusionsphere Openstack
May 13, 2026
Dec 22, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default. An attacker could intercept packets transferred by a target d...Show more
Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default. An attacker could intercept packets transferred by a target device. Successful exploit could cause an information leak.Show less
1Samsung
1Internet Browser
May 13, 2026
Dec 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
1Cambiumnetworks
5Cnpilot E400 Firmware
Cnpilot E410 FirmwareCnpilot E600 Firmware+2 more
May 13, 2026
Dec 20, 2017
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.