← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Windows 10
Windows 8.1Windows Server 2012
May 6, 2026
Apr 12, 2016
N/A· v4
7.1 HIGH· v3
2.1 LOW· v2
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure V...Show more
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits us...Show more
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.Show less
2Apache
Fedoraproject
2Fedora
Qpid Proton
May 6, 2026
Apr 12, 2016
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SS...Show more
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.Show less
1Openstack
1Nova
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary fil...Show more
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.Show less
2Debian
Redmine
2Debian Linux
Redmine
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.
2Debian
Redmine
2Debian Linux
Redmine
May 6, 2026
Apr 12, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with rela...Show more
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.Show less
1Atlassian
1Confluence
May 6, 2026
Apr 11, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
2Kubernetes
Redhat
2Kubernetes
Openshift
May 6, 2026
Apr 11, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.
1Redhat
2Cloudforms
Cloudforms Management Engine
May 6, 2026
Apr 11, 2016
N/A· v4
5.1 MEDIUM· v3
1.9 LOW· v2
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive d...Show more
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.Show less
1Mantisbt
1Mantisbt
May 6, 2026
Apr 11, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API reque...Show more
Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API request.Show less
1Apache
1Openmeetings
May 6, 2026
Apr 11, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which...Show more
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arbitrary files by attempting to upload a file.Show less
1Apache
1Openmeetings
May 6, 2026
Apr 11, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user...Show more
The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.Show less
1Djangoproject
1Django
May 6, 2026
Apr 8, 2016
N/A· v4
3.1 LOW· v3
2.6 LOW· v2
The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.
2Opensuse
Suse
6Leap
Linux Enterprise DesktopLinux Enterprise Server+3 more
May 6, 2026
Apr 8, 2016
N/A· v4
6.2 MEDIUM· v3
2.1 LOW· v2
The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and...Show more
The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Linux Enterprise (SLE) 12.1 and openSUSE Leap 42.1 allows local users to discover database credentials by listing a process and its arguments.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Apr 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Apr 7, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
3Erlang
OpensuseOracle
3Erlang/otp
OpensuseSolaris
May 6, 2026
Apr 7, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of...Show more
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).Show less
1Sap
1Netweaver Application Server Java
May 6, 2026
Apr 7, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~...Show more
The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~rtc~coll.appl.rtc~wd_chat/Chat#, pressing "Add users", and doing a search, aka SAP Security Note 2255990.Show less
1Netapp
1Clustered Data Ontap
May 6, 2026
Apr 7, 2016
N/A· v4
6.8 MEDIUM· v3
5.8 MEDIUM· v2
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Eaton Lighting Systems
1Eg2 Web Control
May 6, 2026
Apr 6, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequently discover credentials, via a direct request.