← Back
CWE-200

10,496 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,496)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Foxitsoftware
1Foxit Reader
May 13, 2026
Oct 31, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must vis...Show more
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4737.Show less
1Mcafee
1Network Data Loss Prevention
May 13, 2026
Oct 31, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and...Show more
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the intended content type.Show less
1Mcafee
1Network Data Loss Prevention
May 13, 2026
Oct 31, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on th...Show more
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver.Show less
1Xen
1Xen
May 13, 2026
Oct 30, 2017
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assum...Show more
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.Show less
1Apache
1Wicket
May 13, 2026
Oct 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
1Artica
1Pandora Fms
May 13, 2026
Oct 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies that general OS information is leaked (e.g., a /var/www pathname typic...Show more
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies that general OS information is leaked (e.g., a /var/www pathname typically means Linux or UNIX).Show less
2Debian
Google
2Chrome
Debian Linux
May 13, 2026
Oct 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
1Google
1Chrome
May 13, 2026
Oct 27, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, r...Show more
Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.Show less
1Google
1Chrome
May 13, 2026
Oct 27, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML pa...Show more
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.Show less
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
May 13, 2026
Oct 27, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via...Show more
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Oct 26, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpredictable numbers. This weakness may allow attackers to expose sensitiv...Show more
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpredictable numbers. This weakness may allow attackers to expose sensitive information by guessing tokens or identifiers. IBM X-Force ID: 123909.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Oct 26, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable the secure cookie attribute. An attacker could exploit...Show more
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable the secure cookie attribute. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 123907.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Oct 26, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) generates an error message in error logs that includes sensitive information about its environment which could be used in further attacks against the system....Show more
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) generates an error message in error logs that includes sensitive information about its environment which could be used in further attacks against the system. IBM X-Force ID: 123905.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Oct 26, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, refer...Show more
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123904.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Oct 26, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123860.
1Ibm
1Rational Collaborative Lifecycle Management
May 13, 2026
Oct 25, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage. IBM X-Force ID: 125157.
1Ibm
1Rational Collaborative Lifecycle Management
May 13, 2026
Oct 25, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace information to an attacker. IBM X-Force ID: 124523.
1Ibm
1Liberty
May 13, 2026
Oct 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by improper error handling by MyFaces in JSF.
1Ibm
1Daeja Viewone
May 13, 2026
Oct 24, 2017
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.
2Cloudfoundry
Pivotal Software
3Cf Release
Cloud Foundry Elastic RuntimeCloud Foundry Uaa
May 13, 2026
Oct 24, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery l...Show more
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."Show less