← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an uni...Show more
mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface.Show less
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a function call that specifies the same buffer for input and output.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Sep 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 25, 2016
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.
1Emc
2Rsa Identity Management And Governance
Rsa Via Lifecycle And Governance
May 6, 2026
Sep 24, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a...Show more
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.Show less
1Mozilla
1Firefox
May 6, 2026
Sep 22, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favic...Show more
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.Show less
1Mozilla
1Firefox
May 6, 2026
Sep 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
1Fortinet
1Fortiwan
May 6, 2026
Sep 21, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request.
1Fortinet
1Fortiwan
May 6, 2026
Sep 21, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfg_show.php or (2) PCAP files via script/sy...Show more
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfg_show.php or (2) PCAP files via script/system/tcpdump.php.Show less
1Emc
1Avamar Server
May 6, 2026
Sep 21, 2016
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic...Show more
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.Show less
1Emc
1Avamar Server
May 6, 2026
Sep 21, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client...Show more
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.Show less
1Aver
1Eh6108h+ Firmware
May 6, 2026
Sep 19, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent attacks to obtain sens...Show more
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent attacks to obtain sensitive information by reading these strings.Show less
1Cisco
3Ios
Ios XeIos Xr
Apr 22, 2026
Sep 19, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information...Show more
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.Show less
1Trane
1Tracer Sc
May 6, 2026
Sep 19, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an uni...Show more
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.Show less