CWE-200
10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,460)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oracle 1Peoplesoft Enterprise Peopletools May 13, 2026 Apr 24, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows...Show more |
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with l...Show more |
1D Link 1Dvg N5402sp Firmware May 13, 2026 Apr 24, 2017 N/A· v4 9.8 CRITICAL· v3 7.8 HIGH· v2 D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows...Show more |
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to perform a man-in-the-middle attack, thereby ste...Show more |
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unp...Show more |
1Juniper 1Northstar Controller May 13, 2026 Apr 24, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underly...Show more |
1Juniper 1Northstar Controller May 13, 2026 Apr 24, 2017 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading t...Show more |
1Juniper 1Northstar Controller May 13, 2026 Apr 24, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or...Show more |
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services...Show more |
sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program w...Show more |
1Redhat 1Cloudforms Management Engine May 13, 2026 Apr 21, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information. |
1Exagrid 8Ex10000e Firmware Ex13000e FirmwareEx21000e Firmware+5 moreMay 13, 2026 Apr 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another...Show more |
Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates. |
1D Link 3Dap 1353 H/w B1 Firmware Dap 2553 H/w A1 FirmwareDap 3520 H/w A1 FirmwareMay 13, 2026 Apr 21, 2017 N/A· v4 8.1 HIGH· v3 2.6 LOW· v2 D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver. A1 1.16 and earlier reveal wireless passwords and administrative usernames and passwords over SNMP...Show more |
1Netgear 3Wnap320 Firmware Wndap350 FirmwareWndap360 FirmwareMay 13, 2026 Apr 21, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP. |
1Netgear 6Wn604 Firmware Wnap320 FirmwareWnd930 Firmware+3 moreMay 13, 2026 Apr 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unaut...Show more |
A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, remote attacker to download and view any system file by using the affecte...Show more |
1Ibm 1Curam Social Program Management May 13, 2026 Apr 20, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254. |
1Ibm 1Curam Social Program Management May 13, 2026 Apr 20, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have ac...Show more |
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users. |