CWE-200
10,476 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,476)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreMay 13, 2026 Jul 5, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528. |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299. |
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These release...Show more |
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM...Show more |
The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and...Show more |
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the c...Show more |
1Humaxdigital 1Hg100r Firmware May 13, 2026 Jul 4, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin. |
1Cisco 1Prime Collaboration Provisioning May 13, 2026 Jul 4, 2017 N/A· v4 5.1 MEDIUM· v3 3.6 LOW· v2 A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Re...Show more |
1Cisco 1Prime Collaboration Provisioning May 13, 2026 Jul 4, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitive information. More Information: CSCvc82973. Known Affected Releases: 1...Show more |
1Netapp 1Oncommand System Manager May 13, 2026 Jul 3, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup. |
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the exis...Show more |
In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initialized Kibana login screen. If the user enters credentials on this screen...Show more |
1Rockwellautomation 201763 L16awa Series A 1763 L16awa Series B1763 L16bbb Series A+17 moreMay 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B,...Show more |
1Sierra Wireless 2Airlink Raven Xe Firmware Airlink Raven Xt FirmwareMay 13, 2026 Jun 30, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently...Show more |
1Belden Hirschmann 1Gecko Lite Managed Switch Firmware May 13, 2026 Jun 30, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously. |
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private...Show more |
1Tibco 9Jasperreports Library Community Edition Jasperreports Library For Activematrix BpmJasperreports Professional+6 moreMay 13, 2026 Jun 29, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReport...Show more |
1Microsoft 2Windows 10 Windows Server 2016May 13, 2026 Jun 29, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application, aka "Microsoft Graphics Component Information...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Jun 29, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticate...Show more |
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component comm...Show more |