← Back
CWE-200

10,474 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,474)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Tivoli Monitoring
May 13, 2026
Jun 27, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.
1Openvpn
1Openvpn
May 13, 2026
Jun 27, 2017
N/A· v4
7.4 HIGH· v3
4.0 MEDIUM· v2
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.
1Redhat
1Automatic Bug Reporting Tool
May 13, 2026
Jun 26, 2017
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by l...Show more
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.Show less
1Redhat
1Automatic Bug Reporting Tool
May 13, 2026
Jun 26, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages...Show more
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.Show less
2Debian
Eclipse
2Debian Linux
Mosquitto
May 13, 2026
Jun 25, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
1Ibm
1Sterling B2b Integrator
May 13, 2026
Jun 23, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.
1Ibm
1Sterling B2b Integrator
May 13, 2026
Jun 23, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.
1Ibm
1Sterling B2b Integrator
May 13, 2026
Jun 23, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.
1Ibm
1Sterling B2b Integrator
May 13, 2026
Jun 23, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.
1Ibm
1Sterling B2b Integrator
May 13, 2026
Jun 23, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.
1Ibm
1Sterling B2b Integrator
May 13, 2026
Jun 22, 2017
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.
1Ibm
1Sterling B2b Integrator
May 13, 2026
Jun 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.
1Trihedral
1Vtscada
May 13, 2026
Jun 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configurat...Show more
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configuration information.Show less
1Adobe
1Captivate
May 13, 2026
Jun 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Captivate versions 9 and earlier have an information disclosure vulnerability resulting from abuse of the quiz reporting feature in Captivate.
1Lenovo
3Advanced Settings Utility
Toolscenter Dynamic System AnalysisUpdatexpress System Pack Installer
May 13, 2026
Jun 20, 2017
N/A· v4
7.5 HIGH· v3
3.5 LOW· v2
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System...Show more
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.Show less
1Linux
1Linux Kernel
May 13, 2026
Jun 17, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized me...Show more
sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.Show less
1Elastic
1X Pack
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
4.0 MEDIUM· v2
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
1Elastic
1X Pack
May 13, 2026
Jun 16, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules f...Show more
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.Show less
1Elasticsearch
1Output Plugin
May 13, 2026
Jun 16, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.
1Elastic
1Logstash
May 13, 2026
Jun 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.