← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Mar 27, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or bro...Show more
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM Reference #: 2000359.Show less
1F5
14Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+11 more
May 13, 2026
Mar 27, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporarily obtain normally unrecoverable information.
1Moodle
1Moodle
May 13, 2026
Mar 26, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Moodle 3.2.x, global search displays user names for unauthenticated users.
1Mediawiki
1Mediawiki
May 13, 2026
Mar 23, 2017
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x befor...Show more
The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics.Show less
1Mediawiki
1Mediawiki
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via...Show more
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.Show less
1Samsung
6M288ofw Firmware
Nt14u FirmwareX10p Firmware+3 more
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information...Show more
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information or bypass authentication via a brute-force attack.Show less
1Cloudera
2Cloudera Manager
Navigator
May 13, 2026
Mar 23, 2017
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle a...Show more
Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).Show less
1Qnap
1Qts
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in an XOR format within the /etc/config/uLinux.conf configuration file.
1Netiq
1Access Manager
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
1Netiq
1Access Manager
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.
1Netiq
1Access Manager
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consume...Show more
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the original requester.Show less
1Novell
1Netiq Idm Servicenow Driver
May 13, 2026
Mar 23, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.
2Dell
Emc
3Recoverpoint
Recoverpoint For Virtual MachinesRecoverpoint For Virtual Machines
Jul 10, 2026
Mar 21, 2017
N/A· v4
7.5 HIGH· v3
2.6 LOW· v2
EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected s...Show more
EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.Show less
2Opensuse
Sane Backends Project
2Leap
Sane Backends
May 13, 2026
Mar 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
1Ibm
1Algo One
May 13, 2026
Mar 20, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request. IBM Reference #: 1999754.
1Ibm
1Rational Rhapsody Design Manager
May 13, 2026
Mar 20, 2017
N/A· v4
3.1 LOW· v3
2.1 LOW· v2
An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking Attack. A JSON Hijacking Attack may expose to an attacker information passed between the server and th...Show more
An unspecified vulnerability in IBM Rhapsody DM 4.0, 5.0, and 6.0 could allow an attacker to perform a JSON Hijacking Attack. A JSON Hijacking Attack may expose to an attacker information passed between the server and the browser. IBM Reference #: 1999960.Show less
1Ca
2Unified Infrastructure Management
Unified Infrastructure Management Snap
May 13, 2026
Mar 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain...Show more
The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.Show less
1Ibm
1Rational Collaborative Lifecycle Management
May 13, 2026
Mar 20, 2017
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
An undisclosed vulnerability in the CLM applications in IBM Jazz Team Server may allow unauthorized access to user credentials. IBM Reference #: 1999965.
1Cisco
1Prime Optical
May 13, 2026
Mar 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configu...Show more
A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device. The attacker must have valid credentials for the device. More Information: CSCvc65257. Known Affected Releases: 10.6(0.1).Show less
1Qdpm
1Qdpm
May 13, 2026
Mar 17, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.