CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 13, 2026 May 12, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a special...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 May 12, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authentic...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows Server 2012May 13, 2026 May 12, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local authenticated attacker to execute a specially crafted application to obtain kernel information, aka...Show more |
1Microsoft 2Windows 7 Windows Server 2008May 13, 2026 May 12, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka "Microsoft ActiveX Information Disclosure Vulnerability." |
1Microsoft 3Windows 7 Windows Server 2008Windows Server 2012May 13, 2026 May 12, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel I...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 May 12, 2017 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers...Show more |
1Microsoft 2Windows 7 Windows Server 2008May 13, 2026 May 12, 2017 N/A· v4 4.7 MEDIUM· v3 2.1 LOW· v2 The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vuln...Show more |
Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hoo...Show more |
1Invisioncommunity 1Invision Power Board May 13, 2026 May 11, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power...Show more |
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml. |
ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID. |
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map. |
1Adobe 1Experience Manager Forms May 13, 2026 May 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Adobe Experience Manager Forms versions 6.2, 6.1, 6.0 have an information disclosure vulnerability resulting from abuse of the pre-population service in AEM Forms. |
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed. |
1Hikvision 58Ds 2cd2032 I Firmware Ds 2cd2112 I FirmwareDs 2cd2132 I Firmware+55 moreMay 13, 2026 May 6, 2017 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5...Show more |
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472. |
2Nodejs Openssl2Node.js OpensslMay 13, 2026 May 4, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a...Show more |
1Cisco 1Unified Contact Center Enterprise May 13, 2026 May 3, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unauthenticated, remote attacker to retrieve information from agents using t...Show more |
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation. |
3Novell SuseXen6Manager Manager ProxyOpenstack Cloud+3 moreMay 13, 2026 May 3, 2017 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function....Show more |