CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Blackberry 2Workspaces Appliance X Workspaces VappMay 13, 2026 Oct 16, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files. |
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. |
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authe...Show more |
1Microsoft 2Windows 10 Windows Server 2016May 13, 2026 Oct 13, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Microsoft Graphics...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Oct 13, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Serv...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Oct 13, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Oct 13, 2017 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Se...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Oct 13, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Serv...Show more |
ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability...Show more |
ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability...Show more |
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosur...Show more |
1Microsoft 1Internet Explorer May 13, 2026 Oct 13, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Oct 13, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Serv...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreMay 13, 2026 Oct 13, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, allows an information disclosure v...Show more |
Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft Outlook Information Disclosure Vulnerability." |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Oct 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Serv...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Oct 13, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Serv...Show more |
Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks. |
2Graphicsmagick Imagemagick2Graphicsmagick ImagemagickMay 13, 2026 Oct 12, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a...Show more |
1Tiandy 1Tiandy Ip Camera Firmware May 13, 2026 Oct 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as demonstrated by config* files and extendwor...Show more |