← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hikvision
1Ivms 4200
May 13, 2026
Aug 30, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Hikvision iVMS-4200 devices before v2.6.2.7 allow local users to generate password-recovery codes via unspecified vectors.
2Debian
Gnupg
2Debian Linux
Libgcrypt
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the use...Show more
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.Show less
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the application. IBM X-Force ID: 113813.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.
1Apache
1Atlas
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.
1Mapsplugin
1Googlemaps
May 13, 2026
Aug 29, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850.
1Zte
6Gan9.8t101a B Firmware
Hg110 FirmwareMf28g Firmware+3 more
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive i...Show more
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.Show less
1Ibm
1Curam Social Program Management
May 13, 2026
Aug 29, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the incidents of a higher privileged user. IBM X-Force ID: 120915.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.
1Osnexus
1Quantastor
May 13, 2026
Aug 28, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune a...Show more
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.Show less
1Netatmo
1Indoor Module Firmware
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier.
1Gnu
1Emacs
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Emacs 24.4 allows remote attackers to bypass security restrictions.
1Polycom
1Unified Communications Software
May 13, 2026
Aug 25, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability c...Show more
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could contain an administrator's password or other sensitive information.Show less
1D Link
2Dns 320l Firmware
Dns 327l Firmware
May 13, 2026
Aug 25, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to...Show more
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and access_token.Show less