← Back
CWE-200

10,459 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,459)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpmyadmin
1Phpmyadmin
May 6, 2026
Dec 11, 2016
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions...Show more
An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will then expose to the user. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.Show less
1Phpmyadmin
1Phpmyadmin
May 6, 2026
Dec 11, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8),...Show more
An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.Show less
1Phpmyadmin
1Phpmyadmin
May 6, 2026
Dec 11, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6....Show more
A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.Show less
1Phpmyadmin
1Phpmyadmin
May 6, 2026
Dec 11, 2016
N/A· v4
8.1 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to d...Show more
An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has access to a user's browser cookie file to decrypt the username and password. Furthermore, the same initialization vector (IV) is used to hash the username and password stored in the phpMyAdmin cookie. If a user has the same password as their username, an attacker who examines the browser cookie can see that they are the same - but the attacker can not directly decode these values from the cookie as it is still hashed. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.Show less
2Debian
Qemu
2Debian Linux
Qemu
May 6, 2026
Dec 9, 2016
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
1Osgeo
1Mapserver
May 6, 2026
Dec 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
1Ibm
2Api Connect
Network Path Manager
May 6, 2026
Dec 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by lev...Show more
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.Show less
1Ibm
1Ims Enterprise Suite
May 6, 2026
Nov 30, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
1Ibm
1Connections
May 6, 2026
Nov 30, 2016
N/A· v4
2.1 LOW· v3
2.1 LOW· v2
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
1Ibm
1Connections
May 6, 2026
Nov 30, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading an "archaic" e-mail address in a response.
1Ibm
1Connections
May 6, 2026
Nov 30, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to obtain sensitive information by reading a stack trace in a response.
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability."
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 30, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
1Microfocus
4Host Access Management And Security Server
Reflection For The WebReflection Security Gateway+1 more
May 6, 2026
Nov 29, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attacke...Show more
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal. Applies to MSS 12.3 before 12.3.326 and MSS 12.2 before 12.2.342 and RSG 12.1 before 12.1.362 and RWeb 12.3 before 12.3.312 and RWeb 12.2 before 12.2.342 and RWeb 12.1 before 12.1.362 and ZFE 2.0.1 before 2.0.1.18 and ZFE 2.0.0 before 2.0.0.52 and ZFE 1.4.0 before 1.4.0.14.Show less
1Linux
1Linux Kernel
May 6, 2026
Nov 28, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which allows local users to obtain sensitive information from kernel stack me...Show more
The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which allows local users to obtain sensitive information from kernel stack memory by triggering failure of a get_user_ex call.Show less
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the netwo...Show more
IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.Show less
1Drupal
1Drupal
May 6, 2026
Nov 25, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.