← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecified action during the printing of an e-mail message, a different vulnera...Show more
Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecified action during the printing of an e-mail message, a different vulnerability than CVE-2015-7760.Show less
1Apple
1Iphone Os
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a fla...Show more
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmi...Show more
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive information via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IOGraphics in Apple OS X before 10.11 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors.
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app.
1Gollum Project
1Gollum
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.
1Ibm
1Emptoris Sourcing
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain se...Show more
IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain sensitive supplier-bid information via unspecified vectors.Show less
1Ibm
1B2b Advanced Communications
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a resp...Show more
IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields.Show less
1Ibm
13Change And Configuration Management Database
Maximo Asset ManagementMaximo Asset Management Essentials+10 more
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004...Show more
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to obtain sensitive information by reading a (1) backup or (2) debug application file.Show less
1Omron
3Cj2h Plc
Cj2m PlcCx Programmer
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local use...Show more
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it easier for local users to obtain sensitive information by reading a file.Show less
1Omron
1Cx Programmer
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which makes it easier for local users to obtain sensitive information by reading a file.
1Omron
3Cj2h Plc
Cj2m PlcCx Programmer
Jun 2, 2026
Oct 6, 2015
N/A· v4
10.0 CRITICAL· v3
5.0 MEDIUM· v2
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the n...Show more
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive information by sniffing the network during a PLC unlock request.Show less
1Juniper
1Pulse Connect Secure
May 6, 2026
Oct 5, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting dep...Show more
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests.Show less