CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitiv...Show more |
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, whic...Show more |
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated us...Show more |
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capabili...Show more |
The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method. |
2Apple Webkitgtk4Iphone Os SafariTvos+1 moreMay 6, 2026 May 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site. |
Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support. |
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors. |
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive in...Show more |
1Apple 4Iphone Os Mac Os XTvos+1 moreMay 6, 2026 May 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during key-length calculations, which allows attackers to obtain sensitive info...Show more |
The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, which allows remote attackers to obtain sensitive information via unspecif...Show more |
Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app. |
The AMD subsystem in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app. |
2Jenkins Redhat2Jenkins OpenshiftMay 6, 2026 May 17, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global conf...Show more |
2Jenkins Redhat2Jenkins OpenshiftMay 6, 2026 May 17, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration. |
2Jenkins Redhat2Jenkins OpenshiftMay 6, 2026 May 17, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoin...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux FedoraJboss Middleware+1 moreMay 23, 2025 May 17, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow...Show more |
1Ibm 1Websphere Application Server May 6, 2026 May 17, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive inform...Show more |
2Php Redhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 May 16, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls...Show more |
1Ibm 2B2b Advanced Communications Multi Enterprise Integration GatewayMay 6, 2026 May 15, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing th...Show more |