← Back
CWE-200

10,460 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,460)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Linux
2Android
Linux Kernel
May 13, 2026
Feb 8, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderat...Show more
An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31704078. References: QC-CR#1076407.Show less
1Netapp
1Data Ontap
May 13, 2026
Feb 7, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access.
1Netapp
1Clustered Data Ontap
May 13, 2026
Feb 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors.
1Simplesamlphp
1Simplesamlphp
May 13, 2026
Feb 7, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
1Netapp
1Snapdrive
May 13, 2026
Feb 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified vectors.
1Ibm
2Security Key Lifecycle Manager
Tivoli Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
1Ibm
2Security Key Lifecycle Manager
Tivoli Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.
1Ibm
2Security Key Lifecycle Manager
Tivoli Key Lifecycle Manager
May 13, 2026
Feb 7, 2017
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.
1Freebsd
1Freebsd
May 13, 2026
Feb 7, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.
1Zoneminder
1Zoneminder
May 13, 2026
Feb 6, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read loc...Show more
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.Show less
1Openafs
1Openafs
May 13, 2026
Feb 6, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
1Linux
1Linux Kernel
May 13, 2026
Feb 6, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances...Show more
Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information from uninitialized heap-memory locations in opportunistic circumstances by reading from a pipe after an incorrect buffer-release decision.Show less
1Dell
1Bsafe Crypto J
May 13, 2026
Feb 3, 2017
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not...Show more
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed the modified PKCS#12 file to the toolkit and guess the current MAC one byte at a time. This is possible because Crypto-J uses a non-constant-time method to compare the stored MAC with the calculated MAC. This vulnerability is similar to the issue described in CVE-2015-2601.Show less
1Emc
1Powerpath Virtual Appliance
May 13, 2026
Feb 3, 2017
N/A· v4
6.4 MEDIUM· v3
6.0 MEDIUM· v2
EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users...Show more
EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users to compromise the affected system.Show less
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 2, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerab...Show more
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
1Security Key Lifecycle Manager
May 13, 2026
Feb 2, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.
1Ibm
1Dashboard Application Services Hub
May 13, 2026
Feb 2, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensit...Show more
IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.Show less
1Ibm
1Infosphere Datastage
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser histor...Show more
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history.Show less
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount further attacks against the system.
1Ibm
2Bigfix Inventory
License Metric Tool
May 13, 2026
Feb 1, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.