← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Spss Modeler
May 6, 2026
Feb 15, 2016
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain se...Show more
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.Show less
2Openssl
Oracle
6Exalogic Infrastructure
OpensslOss Support Tools+3 more
May 6, 2026
Feb 15, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by perfor...Show more
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.Show less
1Ibm
1Qradar Security Information And Event Manager
May 6, 2026
Feb 15, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstati...Show more
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.Show less
4Debian
FedoraprojectMozilla+1 more
5Debian Linux
FedoraFirefox+2 more
May 6, 2026
Feb 13, 2016
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attack...Show more
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.Show less
1Tollgrade
1Smartgrid Lighthouse Sensor Management System
May 6, 2026
Feb 13, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.
1Cisco
1Spark
May 6, 2026
Feb 12, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The REST interface in Cisco Spark 2015-06 allows remote authenticated users to obtain sensitive information via a request for an unspecified file, aka Bug ID CSCuv84048.
1Adobe
1Experience Manager
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.
2Adobe
Apache
2Experience Manager
Sling
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
1Ipswitch
1Moveit Dmz
May 6, 2026
Feb 10, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP request...Show more
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.Show less
1Ipswitch
1Moveit Dmz
May 6, 2026
Feb 10, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID param...Show more
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.Show less
1Ipswitch
2Moveit Dmz
Moveit Mobile
May 6, 2026
Feb 10, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileI...Show more
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.Show less
1Microsoft
1Edge
May 6, 2026
Feb 10, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge mishandles exceptions during window-message dispatch operations, which allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge ASLR Bypass."
1Microsoft
1Internet Explorer
May 6, 2026
Feb 10, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka "...Show more
The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka "Internet Explorer Information Disclosure Vulnerability."Show less
1Microsoft
1.net Framework
May 6, 2026
Feb 10, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure...Show more
WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process memory via crafted icon data, aka "Windows Forms Information Disclosure Vulnerability."Show less
4Samsung
SunZyxel+1 more
4Gs1900 10hp Firmware
Keymouse FirmwareOpensolaris+1 more
May 6, 2026
Feb 9, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express...Show more
Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext encryption key, which allows local users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuv85958.Show less
1Zyxel
1Gs1900 10hp Firmware
May 6, 2026
Feb 9, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy110...Show more
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to obtain sensitive database table-name and entity-name information via a direct request to an unspecified URL, aka Bug ID CSCuy11098.Show less
1Cisco
1Telepresence Video Communication Server Software
May 6, 2026
Feb 9, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct request to an unspecif...Show more
Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct request to an unspecified URL, aka Bug ID CSCux73362.Show less
1Apache
1Cloudstack
May 6, 2026
Feb 8, 2016
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
1Ibm
1Websphere Mq
May 6, 2026
Feb 8, 2016
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allow...Show more
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive information by reading this file.Show less
1Linux
1Linux Kernel
May 6, 2026
Feb 8, 2016
N/A· v4
6.8 MEDIUM· v3
5.6 MEDIUM· v2
Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and sy...Show more
Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free and system crash) by making a TIOCGETD ioctl call during processing of a TIOCSETD ioctl call.Show less