CWE-200
10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,479)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file. |
1Humaxdigital 1Hg100r Firmware May 13, 2026 Jul 19, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the router is configured to ex...Show more |
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL. |
Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. |
1Kaspersky 1Anti Virus For Linux Server May 13, 2026 Jul 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary...Show more |
1Netapp 1Clustered Data Ontap May 13, 2026 Jul 17, 2017 N/A· v4 6.5 MEDIUM· v3 5.0 MEDIUM· v2 NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line. |
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection...Show more |
In Moodle 3.3, the course overview block reveals activities in hidden courses. |
Moodle 3.x has user fullname disclosure on the user preferences page. |
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure. |
The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backu...Show more |
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited with...Show more |
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored pa...Show more |
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure. |
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vuln...Show more |
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack. |
6Apache AppleDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 13, 2026 Jul 13, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_d...Show more |
1Ibm 2Bigfix Inventory License Metric ToolMay 13, 2026 Jul 13, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853. |
2Datataker Thermofisher2Dt80 Dex Firmware Dt80 Dex FirmwareApr 30, 2026 Jul 12, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI. |
1Microsoft 9Edge Internet ExplorerWindows 10+6 moreMay 13, 2026 Jul 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security...Show more |