← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
May 6, 2026
May 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitiv...Show more
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.Show less
1Moodle
1Moodle
May 6, 2026
May 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, whic...Show more
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.Show less
1Moodle
1Moodle
May 6, 2026
May 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated us...Show more
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.Show less
1Moodle
1Moodle
May 6, 2026
May 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capabili...Show more
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover student e-mail addresses by leveraging the teacher role and reading a Participants list.Show less
1Safemode Project
1Safemode
May 6, 2026
May 20, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.
2Apple
Webkitgtk
4Iphone Os
SafariTvos+1 more
May 6, 2026
May 20, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site.
1Apple
1Mac Os X
May 6, 2026
May 20, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.
1Apple
1Iphone Os
May 6, 2026
May 20, 2016
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.
1Apple
2Iphone Os
Safari
May 6, 2026
May 20, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive in...Show more
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
May 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive info...Show more
CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive information via a crafted app.Show less
1Apple
3Iphone Os
Mac Os XTvos
May 6, 2026
May 20, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecif...Show more
The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecified vectors.Show less
1Apple
1Mac Os X
May 6, 2026
May 20, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app.
1Apple
1Mac Os X
May 6, 2026
May 20, 2016
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
May 17, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global conf...Show more
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
May 17, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
May 17, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoin...Show more
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.Show less
4Debian
FedoraprojectRedhat+1 more
4Debian Linux
FedoraJboss Middleware+1 more
May 23, 2025
May 17, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow...Show more
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.Show less
1Ibm
1Websphere Application Server
May 6, 2026
May 17, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive inform...Show more
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls...Show more
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path function in ext/standard/streamsfuncs.c, as demonstrated by a filename\0.extension attack that bypasses an intended configuration in which client users may read files with only one specific extension.Show less
1Ibm
2B2b Advanced Communications
Multi Enterprise Integration Gateway
May 6, 2026
May 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing th...Show more
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network.Show less