← Back
CWE-200

10,498 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Blogotext Project
1Blogotext
May 13, 2026
Dec 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on W...Show more
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the archiv~1.zip name (aka an 8.3 filename).Show less
1Paid To Read Script Project
1Paid To Read Script
May 13, 2026
Dec 20, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
1Meinbergglobal
1Lantime Firmware
May 13, 2026
Dec 19, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to c...Show more
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.Show less
1Apache
1Sling Authentication Service
May 13, 2026
Dec 18, 2017
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.
2Heketi Project
Redhat
2Enterprise Linux
Heketi
May 13, 2026
Dec 18, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
1Cmsmadesimple
1Cms Made Simple
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
1Cmsmadesimple
1Cms Made Simple
May 13, 2026
Dec 18, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
1Pandora
1Pandora
May 13, 2026
Dec 16, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
1Acti
1Camera Firmware
May 13, 2026
Dec 16, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name...Show more
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.Show less
1Fortinet
2Forticlient
Forticlient Sslvpn Client
May 13, 2026
Dec 15, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions a...Show more
An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.Show less
1Cisco
5Adaptive Security Appliance 5505 Firmware
Adaptive Security Appliance 5510 FirmwareAdaptive Security Appliance 5520 Firmware+2 more
May 13, 2026
Dec 15, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Ret...Show more
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.Show less
1Hp
1Synaptics Touchpad Driver
May 13, 2026
Dec 15, 2017
N/A· v4
5.1 MEDIUM· v3
3.6 LOW· v2
A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.
1Meinbergglobal
1Lantime Firmware
May 13, 2026
Dec 15, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging failure to restrict URL access.
1Techno Portfolio Management Panel Project
1Techno Portfolio Management Panel
May 13, 2026
Dec 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php.
2Debian
Phusion
2Debian Linux
Passenger
May 13, 2026
Dec 14, 2017
N/A· v4
4.7 MEDIUM· v3
1.2 LOW· v2
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary f...Show more
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.Show less
1Fortinet
1Fortios
May 13, 2026
Dec 13, 2017
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which...Show more
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_admin privileges to view the current SSL VPN web portal session info which may contains user credentials through the fnsysctl CLI command.Show less
1Symantec
1Norton Family
May 13, 2026
Dec 13, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Prior to 4.4.1.10, the Norton Family Android App can be susceptible to an Information Disclosure issue. Information disclosure is a very common issue that attackers will attempt to exploit as a first pass across the appl...Show more
Prior to 4.4.1.10, the Norton Family Android App can be susceptible to an Information Disclosure issue. Information disclosure is a very common issue that attackers will attempt to exploit as a first pass across the application. As they probe the application they will take note of anything that may seem out of place or any bit of information they can use to their advantage such as error messages, system information, user data, version numbers, component names, URL paths, or even simple typos and misspellings.Show less
1Citrix
2Application Delivery Controller Firmware
Netscaler Gateway Firmware
May 13, 2026
Dec 13, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensiti...Show more
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client Certificates and a Diffie-Hellman Ephemeral (DHE) key exchange.Show less
1Microsoft
1Office
May 13, 2026
Dec 12, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability".
1Microsoft
1Office
May 13, 2026
Dec 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Informatio...Show more
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability".Show less