← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
2Arcsight Enterprise Security Manager
Arcsight Enterprise Security Manager Express
May 13, 2026
Sep 30, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
1Percona
2Toolkit
Xtrabackup
May 13, 2026
Sep 29, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to...Show more
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.Show less
1Percona
1Toolkit
May 13, 2026
Sep 29, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configurati...Show more
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to download configuration information from v.percona.com.Show less
1Laravel
1Laravel
May 13, 2026
Sep 28, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
2Fedoraproject
Wesnoth
2Battle For Wesnoth
Fedora
May 13, 2026
Sep 26, 2017
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is u...Show more
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.Show less
2Fedoraproject
Wesnoth
2Battle For Wesnoth
Fedora
May 13, 2026
Sep 26, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensiti...Show more
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.Show less
1Schneider Electric
1U.motion Builder
May 13, 2026
Sep 26, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an una...Show more
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.Show less
1Magento
1Magento
May 13, 2026
Sep 26, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external se...Show more
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the referrer field.Show less
1Redhat
1Openshift
May 13, 2026
Sep 26, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.
1Dropbox
1Dropbox Sdk
May 13, 2026
Sep 26, 2017
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
1Unify
10Openscape Desk Phone Ip 35g Eco Sip Firmware
Openscape Desk Phone Ip 35g Hfa FirmwareOpenscape Desk Phone Ip 35g Sip Firmware+7 more
May 13, 2026
Sep 25, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G Eco SIP V3, OpenStage 60 and OpenScape Desk Phone IP 55G HFA V3, OpenS...Show more
OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G Eco SIP V3, OpenStage 60 and OpenScape Desk Phone IP 55G HFA V3, OpenStage 15, 20E, 20, and 40 and OpenScape Desk Phone IP 35G HFA V3, and OpenScape Desk Phone IP 35G Eco HFA V3 use non-unique X.509 certificates and SSH host keys.Show less
1Huawei
7Ar1200 Firmware
Ar200 FirmwareAr2200 Firmware+4 more
May 13, 2026
Sep 25, 2017
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.
1Ibm
1Business Process Manager
May 13, 2026
Sep 25, 2017
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.
1Ca
2Identity Manager
Identity Manager Virtual Appliance
May 13, 2026
Sep 22, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
1Asp4cms
1Aspcms
May 13, 2026
Sep 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.
1Zkteco
1Zktime Web
May 13, 2026
Sep 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
1Google
1Android
May 13, 2026
Sep 21, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock.
1Google
1Android
May 13, 2026
Sep 21, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
1Google
1Android
May 13, 2026
Sep 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.
1Google
1Android
May 13, 2026
Sep 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.