← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 13, 2026
Sep 21, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the devi...Show more
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory violation/out of bounds access.Show less
1Chef
1Chef
May 13, 2026
Sep 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
1Freeipa
1Freeipa
May 13, 2026
Sep 21, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
1Iterm2
1Iterm2
May 13, 2026
Sep 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature was added to iTerm2 version 3.0.0 (and unreleased 2.9.x versions such as 2.9.20150717) that resulted i...Show more
iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature was added to iTerm2 version 3.0.0 (and unreleased 2.9.x versions such as 2.9.20150717) that resulted in a potential information disclosure. In an attempt to see whether the text under the cursor (or selected text) was a URL, the text would be sent as an unencrypted DNS query. This has the potential to result in passwords and other sensitive information being sent in cleartext without the user being aware.Show less
1Simple Ads Manager Project
1Simple Ads Manager
May 13, 2026
Sep 20, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
1Huawei
1P8 Firmware
May 13, 2026
Sep 20, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Huawei P8 before GRA-CL00C92B210, before GRA-L09C432B200, before GRA-TL00C01B210, and before GRA-UL00C00B210 allows remote attackers to obtain user equipment (aka UE) measurements of signal strengths.
1Twsz
1Wifi Repeater Firmware
May 13, 2026
Sep 20, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter.
1Polycom
1Realpresence Resource Manager
May 13, 2026
Sep 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager.
1Redhat
1Jboss Enterprise Application Platform
May 13, 2026
Sep 19, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logg...Show more
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.Show less
1Netsweeper
1Netsweeper
May 13, 2026
Sep 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that redirects to the deny page.
1Redhat
1Edeploy
May 13, 2026
Sep 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.
1Apache
1Tomcat
May 13, 2026
Sep 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted...Show more
When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.Show less
1Moodle
1Moodle
May 13, 2026
Sep 18, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
1Google
1Android
May 13, 2026
Sep 14, 2017
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
1Google
1Android
May 13, 2026
Sep 14, 2017
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.
1Fastly
1Fastly
May 13, 2026
Sep 14, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involvi...Show more
The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses.Show less
1Ibm
1Jazz Reporting Service
May 13, 2026
Sep 14, 2017
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.
1Kubernetes
1Kubernetes
May 13, 2026
Sep 14, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on...Show more
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.Show less
1Drupal
1Drupal
May 13, 2026
Sep 13, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of username...Show more
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.Show less
1Eyesofnetwork
1Eyesofnetwork
May 13, 2026
Sep 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file inclusion via the tool_list parameter (aka the url_tool variable) to module/tool_all/select_tool.php, as demonstrated by a tool_list=php://filter/ subs...Show more
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file inclusion via the tool_list parameter (aka the url_tool variable) to module/tool_all/select_tool.php, as demonstrated by a tool_list=php://filter/ substring.Show less