← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Jabber
May 6, 2026
Dec 26, 2015
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.
1Adcon
1A840 Telemetry Gateway Base Station Firmware
May 6, 2026
Dec 24, 2015
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file pathnames via unspecified vectors.
1Adcon
1A840 Telemetry Gateway Base Station Firmware
May 6, 2026
Dec 24, 2015
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing the network.
1Adcon
1A840 Telemetry Gateway Base Station Firmware
May 6, 2026
Dec 24, 2015
N/A· v4
8.7 HIGH· v3
5.8 MEDIUM· v2
The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading clear...Show more
The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support.Show less
1Ewon
1Ewon Firmware
May 6, 2026
Dec 23, 2015
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) th...Show more
eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.Show less
1Ewon
1Ewon Firmware
May 6, 2026
Dec 23, 2015
N/A· v4
8.5 HIGH· v3
5.0 MEDIUM· v2
eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
1Ewon
1Ewon Firmware
May 6, 2026
Dec 23, 2015
N/A· v4
9.9 CRITICAL· v3
5.0 MEDIUM· v2
eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive information via an unspecified URL.
1Motorola
1Moscad Ip Gateway Firmware
May 6, 2026
Dec 23, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
1Eaton
1Proview
May 6, 2026
Dec 23, 2015
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive...Show more
Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.Show less
1Honeywell
2Midas Black Firmware
Midas Firmware
May 6, 2026
Dec 21, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sniffing the network.
1Symantec
1Endpoint Encryption
May 6, 2026
Dec 18, 2015
N/A· v4
N/A· v3
2.3 LOW· v2
EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump.
1Cisco
1Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter
May 6, 2026
Dec 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.
1Token Insert Entity Project
1Token Insert Entity
May 6, 2026
Dec 17, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly o...Show more
The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node.Show less
1Chat Room Project
1Chat Room
May 6, 2026
Dec 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read mess...Show more
The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt r...Show more
The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted Jav...Show more
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.Show less
1Cisco
1Secure Firewall Management Center
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecifi...Show more
Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.Show less
1Cisco
1Hosted Collaboration Solution
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka...Show more
Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374.Show less