← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Ultra Services Platform
May 13, 2026
Aug 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information. The vulnerability is due to the...Show more
A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote attacker to acquire sensitive information. The vulnerability is due to the transmission of sensitive information as part of a GET request. An attacker could exploit this vulnerability by sending a GET request to a vulnerable device. An exploit could allow the attacker to view information regarding the Ultra Services Platform deployment. Cisco Bug IDs: CSCvd76406. Known Affected Releases: 21.0.v0.65839.Show less
1Cisco
1Elastic Services Controller
May 13, 2026
Aug 17, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information. The vulnerability is due to insufficient protectio...Show more
A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to acquire sensitive system information. The vulnerability is due to insufficient protection of sensitive files on the system. An attacker could exploit this vulnerability by logging into the ConfD server and executing certain commands. An exploit could allow an unprivileged user to view configuration parameters that can be maliciously used. Cisco Bug IDs: CSCvd76409. Known Affected Releases: 2.3, 2.3(2).Show less
1Cisco
1Elastic Services Controller
May 13, 2026
Aug 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker c...Show more
A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by authenticating to the application and navigating to certain configuration files. An exploit could allow the attacker to view sensitive system configuration files. Cisco Bug IDs: CSCvd29408. Known Affected Releases: 2.3(2).Show less
1Cisco
1Ultra Services Framework
May 13, 2026
Aug 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information. The vulnerability is due to insufficient protection o...Show more
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by browsing to a specific URL of an affected device. An exploit could allow the attacker to view sensitive configuration information about the deployment. Cisco Bug IDs: CSCvd29358. Known Affected Releases: 21.0.v0.65839.Show less
1Google
1Android
May 13, 2026
Aug 16, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.
1Google
1Android
May 13, 2026
Aug 16, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is casted to a structure without checking if the source buffer is large enough.
1Google
1Android
May 13, 2026
Aug 16, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspace.
1Google
1Android
May 13, 2026
Aug 16, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to userspace by an audio driver.
1Xen
1Xen
May 13, 2026
Aug 15, 2017
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the...Show more
Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.Show less
1Ibm
1Emptoris Strategic Supply Management
May 13, 2026
Aug 14, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could ex...Show more
IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 116881.Show less
1Fortinet
1Fortimanager Firmware
May 13, 2026
Aug 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Aug 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability related to execution of malicious attachments.
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 13, 2026
Aug 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an information disclosure vulnerability when handling links in a PDF document.
1Adobe
1Experience Manager
May 13, 2026
Aug 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability.
1Adobe
1Experience Manager
May 13, 2026
Aug 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Experience Manager 6.3 and earlier has a misconfiguration vulnerability.
1Adobe
1Digital Editions
May 13, 2026
Aug 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.
1Adobe
5Acrobat
Acrobat DcAcrobat Reader+2 more
May 13, 2026
Aug 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (E...Show more
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.Show less
1Google
1Android
May 13, 2026
Aug 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Userspace-controlled non null terminated parameter for IPA WAN ioctl in all Qualcomm products with Android releases from CAF using the Linux kernel can lead to exposure of kernel memory.
1Google
1Android
May 13, 2026
Aug 11, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver.
1Fortinet
1Fortiweb
May 13, 2026
Aug 10, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.