← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Iphone Os
May 6, 2026
Jul 22, 2016
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.
1Ibm
1Maximo Asset Management
May 6, 2026
Jul 17, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive URL information by reading log files.
1Ibm
1Personal Communications
May 6, 2026
Jul 17, 2016
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim accou...Show more
IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.Show less
1Ibm
2Rational Collaborative Lifecycle Management
Rational Team Concert
May 6, 2026
Jul 15, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allow...Show more
The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecycle Management 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 allows remote authenticated users to obtain sensitive information via a malformed request.Show less
1Ibm
1Security Identity Manager Adapter
May 6, 2026
Jul 15, 2016
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process...Show more
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext passwords by (1) reading a configuration file or (2) examining a process.Show less
1Ibm
2Security Directory Server
Tivoli Directory Server
May 6, 2026
Jul 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and...Show more
Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and IBM Security Directory Server (ISDS) before 6.3.1.18-ISS-ISDS-IF0018 and 6.4.x before 6.4.0.9-ISS-ISDS-IF0009 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.Show less
1Tollgrade
1Lighthouse Sms
May 6, 2026
Jul 15, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a se...Show more
Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.Show less
1Cisco
2Asr 5000
Asr 5000 Software
May 6, 2026
Jul 15, 2016
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.
2Kde
Opensuse
3Kde Frameworks
LeapOpensuse
May 6, 2026
Jul 13, 2016
N/A· v4
8.4 HIGH· v3
2.1 LOW· v2
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by r...Show more
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.Show less
1Microsoft
2Edge
Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
1Microsoft
2Edge
Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microso...Show more
The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."Show less
1Microsoft
4Windows 10
Windows 7Windows Rt 8.1+1 more
May 6, 2026
Jul 13, 2016
N/A· v4
2.8 LOW· v3
2.1 LOW· v2
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles page-fault system calls, which allows local users to obtain sensitive information from an arbi...Show more
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles page-fault system calls, which allows local users to obtain sensitive information from an arbitrary process via a crafted application, aka "Windows Kernel Information Disclosure Vulnerability."Show less
1Microsoft
1Edge
May 6, 2026
Jul 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
1Microsoft
1Windows 10
May 6, 2026
Jul 13, 2016
N/A· v4
5.0 MEDIUM· v3
2.1 LOW· v2
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosu...Show more
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability."Show less
1Microsoft
1.net Framework
May 6, 2026
Jul 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related...Show more
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."Show less
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
May 6, 2026
Jul 13, 2016
N/A· v4
2.8 LOW· v3
2.1 LOW· v2
The GDI component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 a...Show more
The GDI component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to obtain sensitive kernel-address information via a crafted application, aka "Win32k Information Disclosure Vulnerability."Show less
2Canonical
Redhat
2Openstack
Openstack Ironic
May 6, 2026
Jul 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address o...Show more
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.Show less
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28402240.
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28522274.