← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Security Network Protection Firmware
May 6, 2026
Jan 18, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collision.
1Netapp
1Data Ontap
May 6, 2026
Jan 18, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.
1Ibm
1Jazz Reporting Service
May 6, 2026
Jan 17, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vector...Show more
Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.Show less
1Ibm
1Infosphere Master Data Management
May 6, 2026
Jan 17, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local us...Show more
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.Show less
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Jan 16, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.
1Sap
1Netweaver
May 6, 2026
Jan 15, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.
1Openstack
1Nova
May 6, 2026
Jan 15, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen ba...Show more
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.Show less
3Canonical
FfmpegOpensuse
3Ffmpeg
LeapUbuntu Linux
May 6, 2026
Jan 15, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL st...Show more
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.Show less
3Canonical
FfmpegOpensuse
3Ffmpeg
LeapUbuntu Linux
May 6, 2026
Jan 15, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL str...Show more
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.Show less
1Advantech
1Webaccess
May 6, 2026
Jan 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.
1Samsung
1Web Viewer
May 6, 2026
Jan 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.
1Advantech
1Webaccess
May 6, 2026
Jan 15, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.
5Apple
HpOpenbsd+2 more
6Linux
Mac Os XOpenssh+3 more
May 29, 2026
Jan 14, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buff...Show more
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.Show less
1Microsoft
6Excel
OfficePowerpoint+3 more
May 6, 2026
Jan 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPo...Show more
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Microsoft Office ASLR Bypass."Show less
1Microsoft
8Windows 7
Windows 8Windows 8.1+5 more
May 6, 2026
Jan 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The graphics device interface in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attacker...Show more
The graphics device interface in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows GDI32.dll ASLR Bypass Vulnerability."Show less
1Openstack
1Nova
May 6, 2026
Jan 12, 2016
N/A· v4
3.5 LOW· v3
2.1 LOW· v2
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by ov...Show more
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.Show less
1Huawei
1Vcn500
May 6, 2026
Jan 11, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive information by triggering log generation and then reading the log.
1Ibm
2Integration Bus
Websphere Message Broker
May 6, 2026
Jan 11, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecif...Show more
IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors.Show less
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Jan 8, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Jan 8, 2016
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote a...Show more
ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.Show less