CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user. |
In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user. |
In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user. |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user. |
1Ibm 1Financial Transaction Manager May 13, 2026 Oct 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an undocumented URL. IBM X-Force ID: 130735. |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, information disclosure is possible in function __wlan_hdd_cfg80211_testmode since buffer hb_params is not in...Show more |
salt before 2015.5.5 leaks git usernames and passwords to the log. |
Trapeze TransitMaster is vulnerable to information disclosure (emails / hashed passwords) via a modified userID field in JSON data to ManageSubscriber.aspx/GetSubscriber. NOTE: this software is independently deployed at...Show more |
1Digium 2Asterisk Certified AsteriskMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffe...Show more |
1Infocuscorp 1Infocus Mondopad May 13, 2026 Oct 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-contr...Show more |
The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack. |
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules. |
1Saia Burgess Controls 1Pcd Controllers Firmware May 13, 2026 Oct 5, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An Information Exposure issue was discovered in Saia Burgess Controls PCD Controllers with PCD firmware versions prior to 1.28.16 or 1.24.69. In certain circumstances, the device pads Ethernet frames with memory contents...Show more |
The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. T...Show more |
The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system access, or users with Extended Read access to the jobs it is used in, to...Show more |
1Jenkins 1Pipeline Input Step May 13, 2026 Oct 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission ins...Show more |
When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncated to fit within the buffer boundaries, but the buffer size is still w...Show more |
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doing this would send the wrong buffer to the user (stdout or the applicati...Show more |
Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permission...Show more |
1Jenkins 1Github Branch Source May 13, 2026 Oct 5, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read p...Show more |