← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Slideshow Project
1Slideshow
May 13, 2026
Jun 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.
1Redhat
4Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+1 more
May 13, 2026
Jun 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allow...Show more
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions.Show less
1Redhat
4Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+1 more
May 13, 2026
Jun 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allow...Show more
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.Show less
2Fedoraproject
Pulpproject
2Fedora
Pulp
May 13, 2026
Jun 8, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
1Pulpproject
1Pulp
May 13, 2026
Jun 8, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permi...Show more
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.Show less
1Huawei
1Oceanstor Uds Firmware
May 13, 2026
Jun 8, 2017
N/A· v4
5.0 MEDIUM· v3
3.5 LOW· v2
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.
1Huawei
1Oceanstor Uds Firmware
May 13, 2026
Jun 8, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.
1Ibm
1Cognos Business Intelligence Server
May 13, 2026
Jun 7, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.
1Ibm
1Cognos Business Intelligence Server
May 13, 2026
Jun 7, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow...Show more
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.Show less
1Ibm
1Tivoli Storage Manager
May 13, 2026
Jun 7, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.
1Ibm
1Security Privileged Identity Manager
May 13, 2026
Jun 7, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
1Ibm
1Security Privileged Identity Manager
May 13, 2026
Jun 7, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer h...Show more
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.Show less
1Openstack
1Ironic
May 13, 2026
Jun 7, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
1Personify
1Personify360 E Business
May 13, 2026
Jun 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search...Show more
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required.Show less
1Spice Gtk Project
1Spice Gtk
May 13, 2026
Jun 6, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.
1Google
1Android
May 13, 2026
Jun 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.
1Google
1Android
May 13, 2026
Jun 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.
1Peplink
61350hw2 Firmware
2500 Firmware380hw6 Firmware+3 more
May 13, 2026
Jun 5, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasy...Show more
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted syncid.Show less
1Elastic
1X Pack
May 13, 2026
Jun 5, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have...Show more
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data they should not have access to when performing certain operations against an index alias.Show less
1Lenovo
1Lenovo Service Bridge
May 13, 2026
Jun 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.