← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
May 13, 2026
Sep 13, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allo...Show more
The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly discloses kernel memory addresses, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8678, CVE-2017-8680, CVE-2017-8681, and CVE-2017-8687.Show less
1Microsoft
14Live Meeting
LyncOffice+11 more
May 13, 2026
Sep 13, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016...Show more
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an authenticated attacker to retrieve information from a targeted system via a specially crafted application, aka "Windows GDI+ Information Disclosure Vulnerability."Show less
1Microsoft
1Windows 10
May 13, 2026
Sep 13, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge in Microsoft Windows Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Informa...Show more
Microsoft Edge in Microsoft Windows Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8597 and CVE-2017-8643.Show less
1Microsoft
1Edge
May 13, 2026
Sep 13, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to leave a malicious website open during user clipboard activities, due to the way that Microsoft Edge handles cli...Show more
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to leave a malicious website open during user clipboard activities, due to the way that Microsoft Edge handles clipboard events, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8597 and CVE-2017-8648.Show less
1Microsoft
1Windows 10
May 13, 2026
Sep 13, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Info...Show more
Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8643 and CVE-2017-8648.Show less
1Microsoft
1Exchange Server
May 13, 2026
Sep 13, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Info...Show more
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"Show less
1Ibm
2Db2
Db2 Connect
May 13, 2026
Sep 12, 2017
N/A· v4
4.7 MEDIUM· v3
2.1 LOW· v2
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.
1Ibm
1Qradar Security Information And Event Manager
May 13, 2026
Sep 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 122957.
1Bluez
1Bluez
May 13, 2026
Sep 12, 2017
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vu...Show more
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.Show less
1Ellucian
1Banner Student
May 13, 2026
Sep 11, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.
1Ee
14gee Wifi Mbb Firmware
May 13, 2026
Sep 11, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices allow remote attackers to obtain sensitive information via a JSONP endpoint, as demonstrated by passwords and SMS content.
1Dolibarr
1Dolibarr
May 13, 2026
Sep 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38340117.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
7.1 HIGH· v3
7.8 HIGH· v2
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.
1Google
1Android
May 13, 2026
Sep 8, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.
1Yast
1Yast2
May 13, 2026
Sep 8, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks.
1Kubik Rubik
1Easy Joomla Backup
May 13, 2026
Sep 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename.