CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Meteocontrol 4Web'log Basic 100 Web'log LightWeb'log Pro+1 moreMay 6, 2026 May 14, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors. |
The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-force attack. |
HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors. |
2Apple Filemaker2Filemaker Mac Os XMay 6, 2026 May 14, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors. |
The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) ListAddrByAttributes structures, which might allow remote attackers to...Show more |
3Botan Project DebianFedoraproject3Botan Debian LinuxFedoraMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-...Show more |
3Botan Project DebianFedoraproject3Botan Debian LinuxFedoraMay 6, 2026 May 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding. |
1Adobe 4Acrobat Acrobat DcAcrobat Reader Dc+1 moreMay 6, 2026 May 11, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader Dc+1 moreMay 6, 2026 May 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader Dc+1 moreMay 6, 2026 May 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive...Show more |
Microsoft Internet Explorer 10 and 11 allows remote attackers to bypass file permissions and obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." |
1Microsoft 3Windows 8.1 Windows Rt 8.1Windows Server 2012May 6, 2026 May 11, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB disk accesses originate from the user who mounted a disk, which allows...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 May 11, 2016 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to o...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 May 11, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitiv...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 6, 2026 May 11, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitiv...Show more |
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-...Show more |
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted...Show more |
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted...Show more |
The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive information via a cra...Show more |
1Veritas 2Netbackup Netbackup ApplianceMay 6, 2026 May 7, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS for administration-console traffic to the NBU server, which allows remote...Show more |