← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Mq
May 6, 2026
Jun 26, 2016
N/A· v4
2.5 LOW· v3
2.1 LOW· v2
runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authority requirement and obtain sensitive information via unspecified display commands.
1Cybozu
1Garoon
May 6, 2026
Jun 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.
1Huawei
1Ocean Stor Firmware
May 6, 2026
Jun 24, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and ob...Show more
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and obtain sensitive information by sniffing the network.Show less
1Solarwinds
1Virtualization Manager
May 6, 2026
Jun 24, 2016
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.
1F5
16Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+13 more
May 6, 2026
Jun 24, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11...Show more
The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11.6.1; BIG-IQ Cloud and Security 4.0.0 through 4.5.0; BIG-IQ Device 4.2.0 through 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 4.6.0; and BIG-IQ Cloud and Orchestration 1.0.0 allows remote authenticated administrators to obtain sensitive information via unspecified vectors.Show less
1Netgear
2D3600 Firmware
D6000 Firmware
May 6, 2026
Jun 20, 2016
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the c...Show more
The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the cgi-bin/passrec.asp HTML source code.Show less
1Apple
2Iphone Os
Safari
May 6, 2026
Jun 19, 2016
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
1Apple
1Mac Os X
May 6, 2026
Jun 19, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.
1Apple
1Mac Os X
May 6, 2026
Jun 19, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.
1Cybozu
1Garoon
May 6, 2026
Jun 19, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.
1Cybozu
1Garoon
May 6, 2026
Jun 19, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.
1Cybozu
1Garoon
May 6, 2026
Jun 19, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2...Show more
Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196.Show less
1Ibm
1Websphere Mq
May 6, 2026
Jun 19, 2016
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.
1Trendmicro
1Internet Security
May 6, 2026
Jun 19, 2016
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.
1Buffalo
34Bhr 4grv Firmware
Dwr Hp G300nh FirmwareFs 600dhp Firmware+31 more
May 6, 2026
Jun 19, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive information via unspecified vectors.
1Cisco
1Prime Network Registrar
May 6, 2026
Jun 18, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remote attackers to obtain sensitive information via crafted SCP messages,...Show more
The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remote attackers to obtain sensitive information via crafted SCP messages, aka Bug ID CSCuv35694.Show less
1Microsoft
6Office
Office Compatibility PackOffice Web Apps+3 more
May 6, 2026
Jun 16, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office...Show more
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."Show less
1Microsoft
1Windows Server 2012
May 6, 2026
Jun 16, 2016
N/A· v4
5.0 MEDIUM· v3
2.1 LOW· v2
The Virtual PCI (VPCI) virtual service provider in Microsoft Windows Server 2012 Gold and R2 allows local users to obtain sensitive information from uninitialized memory locations via a crafted application, aka "Windows...Show more
The Virtual PCI (VPCI) virtual service provider in Microsoft Windows Server 2012 Gold and R2 allows local users to obtain sensitive information from uninitialized memory locations via a crafted application, aka "Windows Virtual PCI Information Disclosure Vulnerability."Show less
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
May 6, 2026
Jun 16, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows rem...Show more
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows Graphics Component Information Disclosure Vulnerability."Show less
1Microsoft
4Edge
Windows 10Windows 8.1+1 more
May 6, 2026
Jun 16, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Informat...Show more
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.Show less