← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cloudera
1Hue
May 13, 2026
Mar 7, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.
2Artifex
Debian
2Afpl Ghostscript
Debian Linux
May 13, 2026
Mar 7, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
1Blackberry
1Good Control Server
May 13, 2026
Mar 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain res...Show more
An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain resources within a customer's Good deployment by gaining access to certain diagnostic log files through either a valid logon or an unrelated compromise of the server.Show less
1Dropbear Ssh Project
1Dropbear Ssh
May 13, 2026
Mar 3, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.
1Matrixssl
1Matrixssl
May 13, 2026
Mar 3, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.
1Matrixssl
1Matrixssl
May 13, 2026
Mar 3, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack.
1Owncloud
1Owncloud
May 13, 2026
Mar 3, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via u...Show more
The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via unspecified vectors.Show less
1Owncloud
1Owncloud
May 13, 2026
Mar 3, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows re...Show more
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
May 13, 2026
Mar 3, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances vi...Show more
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilitiesShow less
1Netapp
1Ontap Select Deploy Administration Utility
May 13, 2026
Mar 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors.
1Siemens
3Sinumerik Integrate Access Mymachine/ethernet
Sinumerik Integrate Operate ClientSinumerik Operate
May 13, 2026
Mar 1, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read a...Show more
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.Show less
1Yandex
1Yandex Browser
May 13, 2026
Mar 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a...Show more
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.Show less
5Allwinner
AmdIntel+2 more
20A64
Athlon Ii 640 X4Atom C2750+17 more
May 13, 2026
Feb 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possib...Show more
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.Show less
5Allwinner
AmdIntel+2 more
20A64
Athlon Ii 640 X4Atom C2750+17 more
May 13, 2026
Feb 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possib...Show more
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.Show less
5Allwinner
AmdIntel+2 more
20A64
Athlon Ii 640 X4Atom C2750+17 more
May 13, 2026
Feb 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is poss...Show more
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.Show less
1Plone
1Plone
May 13, 2026
Feb 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.
1Wolfssl
1Wolfssl
May 13, 2026
Feb 24, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine.
1Dlink
1Websmart Dgs 1510 Series Firmware
May 13, 2026
Feb 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure...Show more
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure attacks via unspecified vectors.Show less
1Ibm
1Websphere Mq
May 13, 2026
Feb 22, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques.
1Xen
1Xen
May 13, 2026
Feb 22, 2017
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.