← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
May 13, 2026
Apr 20, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
1Aveva
1Wonderware Intouch Access Anywhere
May 13, 2026
Apr 20, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary de...Show more
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.Show less
1Cybozu
1Mailwise
May 13, 2026
Apr 20, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.
1Cybozu
1Mailwise
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.
1Cybozu
1Mailwise
May 13, 2026
Apr 20, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.
1Ovirt
1Ovirt
May 13, 2026
Apr 20, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.
1Mediawiki
1Mediawiki
May 13, 2026
Apr 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to a...Show more
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.Show less
1Mediawiki
1Mediawiki
May 13, 2026
Apr 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when...Show more
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.Show less
1Redhat
1Openshift
May 13, 2026
Apr 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to...Show more
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.Show less
1Netiq
1Access Manager
May 13, 2026
Apr 20, 2017
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.
1Unitrends
1Enterprise Backup
May 13, 2026
Apr 20, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticat...Show more
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).Show less
1Samsung
1Samsung Mobile
May 13, 2026
Apr 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290.
1Ibm
1Cognos Business Intelligence
May 13, 2026
Apr 17, 2017
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensitive information. IBM X-Force ID: 114613.
1Apache
1Tomcat
May 13, 2026
Apr 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined reques...Show more
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.Show less
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
1Cybozu
1Office
May 13, 2026
Apr 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
1Redhat
1Quickstart Cloud Installer
May 13, 2026
Apr 14, 2017
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
1Ibm
1Tivoli Application Dependency Discovery Manager
May 13, 2026
Apr 14, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539.
1Ibm
1Tivoli Application Dependency Discovery Manager
May 13, 2026
Apr 14, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.