← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Opensuse
Phpmyadmin
3Leap
OpensusePhpmyadmin
May 6, 2026
Jul 3, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to...Show more
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors involving (1) an array value to FormDisplay.php, (2) incorrect data to validate.php, (3) unexpected data to Validator.php, (4) a missing config directory during setup, or (5) an incorrect OpenID identifier data type, which reveals the full path in an error message.Show less
1Vmware
2Nsx Edge
Vcloud Networking And Security Edge
May 6, 2026
Jul 3, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified vectors.
3Ibm
NodejsNpmjs
3Node.js
NpmSdk
May 6, 2026
Jul 2, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTT...Show more
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.Show less
1Ibm
2Integration Bus
Websphere Message Broker
May 6, 2026
Jul 2, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malf...Show more
The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote attackers to obtain sensitive Tomcat version information by sending a malformed POST request and then reading the Java stack trace.Show less
1Ibm
1Tririga Application Platform
May 6, 2026
Jul 2, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to obtain sensitive information by reading HTTP responses.
1Ibm
1Websphere Extreme Scale
May 6, 2026
Jul 2, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive informatio...Show more
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 does not properly encrypt data, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.Show less
1Ibm
1Urbancode Deploy
May 6, 2026
Jul 1, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive...Show more
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled, allows remote attackers to bypass authentication and obtain sensitive artifact information via unspecified vectors.Show less
1Ibm
1Urbancode Deploy
May 6, 2026
Jul 1, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtai...Show more
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 does not properly implement a logging-obfuscation feature for secure properties, which allows remote authenticated users to obtain sensitive information via vectors involving special characters.Show less
1Symantec
1Endpoint Protection Manager
May 6, 2026
Jun 30, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the networ...Show more
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.Show less
1Symantec
1Endpoint Protection Manager
May 6, 2026
Jun 30, 2016
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover the PHP JSESSIONID value via unspecified vectors.
1Symantec
1Endpoint Protection Manager
May 6, 2026
Jun 30, 2016
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.
1Symantec
1Endpoint Protection Manager
May 6, 2026
Jun 30, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.
1Symantec
1Endpoint Protection Manager
May 6, 2026
Jun 30, 2016
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against manageme...Show more
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts, by entering data into the authorization window.Show less
1Redhat
1Openstack
May 6, 2026
Jun 30, 2016
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password o...Show more
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.Show less
1Wordpress
1Wordpress
May 6, 2026
Jun 29, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
1Ibm
1Security Guardium
May 6, 2026
Jun 29, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.
1Ibm
1Urbancode Deploy
May 6, 2026
Jun 29, 2016
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a databa...Show more
IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.Show less
4Fedoraproject
LinuxRedhat+1 more
11Enterprise Linux
FedoraLinux Enterprise Debuginfo+8 more
May 6, 2026
Jun 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by...Show more
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.Show less
1Linux
1Linux Kernel
May 6, 2026
Jun 27, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack mem...Show more
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.Show less
1Linux
1Linux Kernel
May 6, 2026
Jun 27, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The sched_read_attr function in kernel/sched/core.c in the Linux kernel 3.14-rc before 3.14-rc4 uses an incorrect size, which allows local users to obtain sensitive information from kernel stack memory via a crafted sche...Show more
The sched_read_attr function in kernel/sched/core.c in the Linux kernel 3.14-rc before 3.14-rc4 uses an incorrect size, which allows local users to obtain sensitive information from kernel stack memory via a crafted sched_getattr system call.Show less