← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
May 6, 2026
Feb 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read S...Show more
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.Show less
1Moodle
1Moodle
May 6, 2026
Feb 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge informat...Show more
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.Show less
1Moodle
1Moodle
May 6, 2026
Feb 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions...Show more
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain sensitive course-participant information via a web-service request.Show less
1Moodle
1Moodle
May 6, 2026
Feb 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentic...Show more
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics to an arbitrary hub URL.Show less
1Moodle
1Moodle
May 6, 2026
Feb 22, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive info...Show more
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.Show less
1Moodle
1Moodle
May 6, 2026
Feb 22, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which mak...Show more
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.Show less
2Fedoraproject
Phpmyadmin
2Fedora
Phpmyadmin
May 6, 2026
Feb 20, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
3Fedoraproject
OpensusePhpmyadmin
4Fedora
LeapOpensuse+1 more
May 6, 2026
Feb 20, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php...Show more
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.Show less
3Fedoraproject
OpensusePhpmyadmin
4Fedora
LeapOpensuse+1 more
May 6, 2026
Feb 20, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrict...Show more
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.Show less
3Fedoraproject
OpensusePhpmyadmin
4Fedora
LeapOpensuse+1 more
May 6, 2026
Feb 20, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
1Belden
2Hirschmann Firmware
Hirschmann L2b
May 6, 2026
Feb 18, 2016
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows...Show more
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitive information by sniffing the network.Show less
1Symantec
1Encryption Management Server
May 6, 2026
Feb 18, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487.
1Cybozu
1Office
May 6, 2026
Feb 17, 2016
N/A· v4
4.3 MEDIUM· v3
2.6 LOW· v2
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.
1Sap
1Netweaver Application Server Java
Apr 21, 2026
Feb 16, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
1Cisco
1Universal Small Cell Firmware
May 6, 2026
Feb 15, 2016
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive f...Show more
Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID CSCut98082.Show less
1Ibm
1Financial Transaction Manager
May 6, 2026
Feb 15, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.
1Ibm
1Financial Transaction Manager
May 6, 2026
Feb 15, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception detai...Show more
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.Show less
1Openssl
1Openssl
May 6, 2026
Feb 15, 2016
N/A· v4
3.7 LOW· v3
2.6 LOW· v2
The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to...Show more
The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.Show less
1Ibm
1Websphere Commerce
May 6, 2026
Feb 15, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.