← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Tealeaf Consumer Experience
May 13, 2026
May 3, 2017
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be accidentally captured and exposed by network infrastructure components such as IIS. IBM X-Force ID:...Show more
The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be accidentally captured and exposed by network infrastructure components such as IIS. IBM X-Force ID: 112356.Show less
1Paloaltonetworks
1Pan Os
May 13, 2026
May 2, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.
1Advantech
1Webaccess
May 13, 2026
May 2, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.
1Pivotal Software
2Cloud Foundry
Cloud Foundry Elastic Runtime
May 13, 2026
May 2, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.
1Miniprofiler
1Rack Mini Profiler
May 13, 2026
May 2, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.
1Telegram Desktop
1Telegram Desktop
May 13, 2026
May 1, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.
1Paloaltonetworks
1Pan Os
May 13, 2026
Apr 29, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission vali...Show more
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.Show less
1Ibm
1Insights Foundation For Energy
May 13, 2026
Apr 28, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.
1Cybozu
1Kunai
May 13, 2026
Apr 28, 2017
N/A· v4
2.5 LOW· v3
2.6 LOW· v2
Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android application.
1Presentcast Inc
1Tver
May 13, 2026
Apr 28, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1K Opticom Corporation
1Business Lala Call
May 13, 2026
Apr 28, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi...Show more
The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1K Opticom Corporation
1Lala Call
May 13, 2026
Apr 28, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Cybozu
1Garoon
May 13, 2026
Apr 28, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.
1Atlassian
1Confluence Server
May 13, 2026
Apr 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
1Joomla
1Joomla
May 13, 2026
Apr 25, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
1Joomla
1Joomla
May 13, 2026
Apr 25, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
1Saltstack
1Salt
May 13, 2026
Apr 25, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (cli...Show more
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on configured minions (clients).Show less
1Oracle
1Hospitality Opera 5 Property Services
May 13, 2026
Apr 24, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OXI Interface). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5...Show more
Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OXI Interface). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).Show less
1Oracle
1Application Object Library
May 13, 2026
Apr 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: File Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Difficult t...Show more
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: File Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).Show less
1Oracle
1Hospitality Opera 5 Property Services
May 13, 2026
Apr 24, 2017
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Room Image/Picture Setup). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5....Show more
Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Room Image/Picture Setup). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).Show less