← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Imagemagick
1Imagemagick
May 13, 2026
Jul 19, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
1Humaxdigital
1Hg100r Firmware
May 13, 2026
Jul 19, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to ex...Show more
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to expose the management console. The router is not validating the session token while returning answers for some methods in url '/api'. An attacker can use this vulnerability to retrieve sensitive information such as private/public IP addresses, SSID names, and passwords.Show less
1Google
1News And Weather
May 13, 2026
Jul 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL.
1Joomla
1Joomla
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents.
1Kaspersky
1Anti Virus For Linux Server
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary...Show more
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges.Show less
1Netapp
1Clustered Data Ontap
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
1Lenovo
1Connect2
May 13, 2026
Jul 17, 2017
N/A· v4
4.8 MEDIUM· v3
2.3 LOW· v2
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection...Show more
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user's contents could connect to the Connect2 hotspot and see the contents of files while they are being transferred between the two systems.Show less
1Moodle
1Moodle
May 13, 2026
Jul 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Moodle 3.3, the course overview block reveals activities in hidden courses.
1Moodle
1Moodle
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Moodle 3.x has user fullname disclosure on the user preferences page.
1Apache
1Openmeetings
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.
1Jenkins
1Jenkins
May 13, 2026
Jul 17, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backu...Show more
The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backups were world-readable and not removed afterwards. Jenkins now deletes the backup directory, if present. Upgrading from before 1.498 will no longer create a backup directory. Administrators relying on file access permissions in their manually created backups are advised to check them for the directory $JENKINS_HOME/jenkins.security.RekeySecretAdminMonitor/backups, and delete it if present.Show less
1Oracle
1Glassfish Server
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited with...Show more
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.Show less
1Gnome
1Epiphany
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored pa...Show more
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.Show less
1Twistedmatrix
1Txaws
May 13, 2026
Jul 17, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.
1Microsoft
1Edge
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vuln...Show more
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."Show less
1Theforeman
1Foreman
May 13, 2026
Jul 17, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
6Apache
AppleDebian+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+12 more
May 13, 2026
Jul 13, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_d...Show more
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.Show less
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Jul 13, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
2Datataker
Thermofisher
2Dt80 Dex Firmware
Dt80 Dex Firmware
Apr 30, 2026
Jul 12, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
1Microsoft
9Edge
Internet ExplorerWindows 10+6 more
May 13, 2026
Jul 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security...Show more
Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security feature bypass vulnerability when they improperly handle redirect requests, aka "Microsoft Browser Security Feature Bypass".Show less