← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Exemys
1Telemetry Web Server
May 6, 2026
Nov 19, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the...Show more
Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the response body.Show less
1Cisco
1Firepower Extensible Operating System
May 6, 2026
Nov 19, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.
1Cisco
1Firepower Extensible Operating System
May 6, 2026
Nov 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.
1Tibco
1Loglogic Unity
May 6, 2026
Nov 18, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request.
1Emc
1Vplex Geosynchrony
May 6, 2026
Nov 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file.
1Uc Profile Project
1Uc Profile
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user prof...Show more
The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.Show less
1Citrix
3Netscaler Application Delivery Controller Firmware
Netscaler Gateway FirmwareNetscaler Service Delivery Appliance Service Vm
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appl...Show more
The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows attackers to obtain sensitive information via unspecified vectors.Show less
1Citrix
3Netscaler Application Delivery Controller Firmware
Netscaler Gateway FirmwareNetscaler Service Delivery Appliance Service Vm
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Se...Show more
The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.Show less
1Gnu
1Gcc
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict...Show more
The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified vectors.Show less
1Ibm
1Datapower Gateway
May 6, 2026
Nov 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an...Show more
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.Show less
1Ibm
3Tivoli Storage Flashcopy Manager
Tivoli Storage Manager For Databases Data Protection For Microsoft Sql ServerTivoli Storage Manager For Mail Data Protection For Microsoft Exchange Server
May 6, 2026
Nov 14, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; Tivoli Storage Man...Show more
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server (aka Spectrum Protect for Mail) 5.5 before 5.5.1.1, 6.1 and 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; and Tivoli Storage FlashCopy Manager for Windows (aka Spectrum Protect Snapshot) 2.x and 3.1 before 3.1.1.6, 3.2 before 3.2.1.8, and 4.1 before 4.1.4, when application tracing is configured, write cleartext passwords during changetsmpassword command execution, which allows local users to obtain sensitive information by reading the application trace output.Show less
1Cisco
1Videoscape Distribution Suite Service Manager
May 6, 2026
Nov 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive information via crafted URLs in REST API requests, aka Bug ID CSCuv86960.
1Microsoft
1.net Framework
May 6, 2026
Nov 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka ".NET ASLR Bypass."
1Microsoft
4Windows 10
Windows 8.1Windows Rt 8.1+1 more
May 6, 2026
Nov 11, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via...Show more
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory Information Disclosure Vulnerability."Show less
1Microsoft
9Windows 10
Windows 7Windows 8+6 more
May 6, 2026
Nov 11, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local us...Show more
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory Information Disclosure Vulnerability."Show less
1Microsoft
1.net Framework
May 6, 2026
Nov 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference...Show more
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."Show less
1Microsoft
2Edge
Internet Explorer
May 6, 2026
Nov 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."
1Microsoft
1Internet Explorer
May 6, 2026
Nov 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
1Sap
1Hana
May 6, 2026
Nov 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to read web dispatcher and security trace files and possibly obtain passwords via unspecified vectors, aka SAP Security N...Show more
The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to read web dispatcher and security trace files and possibly obtain passwords via unspecified vectors, aka SAP Security Note 2148854.Show less
4Apache
CanonicalDebian+1 more
4Debian Linux
LibreofficeOpenoffice+1 more
May 6, 2026
Nov 10, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to o...Show more
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.Show less