CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read S...Show more |
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge informat...Show more |
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions...Show more |
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentic...Show more |
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive info...Show more |
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which mak...Show more |
2Fedoraproject Phpmyadmin2Fedora PhpmyadminMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php...Show more |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrict...Show more |
3Fedoraproject OpensusePhpmyadmin4Fedora LeapOpensuse+1 moreMay 6, 2026 Feb 20, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. |
1Belden 2Hirschmann Firmware Hirschmann L2bMay 6, 2026 Feb 18, 2016 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows...Show more |
1Symantec 1Encryption Management Server May 6, 2026 Feb 18, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request. |
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487. |
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488. |
1Sap 1Netweaver Application Server Java Apr 21, 2026 Feb 16, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846. |
1Cisco 1Universal Small Cell Firmware May 6, 2026 Feb 15, 2016 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive f...Show more |
1Ibm 1Financial Transaction Manager May 6, 2026 Feb 15, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files. |
1Ibm 1Financial Transaction Manager May 6, 2026 Feb 15, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception detai...Show more |
The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to...Show more |
The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors. |