← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Xcode
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by l...Show more
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.Show less
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a...Show more
The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make it easier for remote attackers to discover a password by leveraging a later prediction containing that character.Show less
1Apple
2Iphone Os
Watchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
CFNetwork in Apple iOS before 9 relies on the hardware UID for its cache encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen st...Show more
Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.Show less
1Apple
3Iphone Os
Mac Os XWatchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CoreAnimation in Apple iOS before 9 allows attackers to bypass intended IOSurface restrictions and obtain screen-framebuffer access via a crafted background app.
1Apple
3Iphone Os
Mac Os XWatchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IOStorageFamily in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive information from kernel memory via unknown vectors.
1Apple
2Iphone Os
Watchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.
1Apple
2Iphone Os
Watchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.
1Apple
2Iphone Os
Watchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apple iOS before 9 allows attackers to discover the e-mail address of a player via a crafted Game Center app.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted...Show more
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.Show less
1Apple
3Iphone Os
Mac Os XWatchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Apple iOS before 9 allows attackers to obtain sensitive information about inter-app communication via a crafted app that conducts an interception attack involving an unspecified URL scheme.
1Apple
2Iphone Os
Watchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IOAcceleratorFamily in Apple iOS before 9 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from the keychain upon a signout action, which might allow physically proximate attackers to obtain sensitive information via...Show more
The iTunes Store component in Apple iOS before 9 does not properly delete AppleID credentials from the keychain upon a signout action, which might allow physically proximate attackers to obtain sensitive information via unspecified vectors.Show less
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sensitive memory-layout information via a crafted app.
1Apple
2Iphone Os
Safari
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) custom event, (2) message event, or (3) pop state event.
1Apple
2Iphone Os
Safari
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traff...Show more
WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.Show less
1Apple
2Iphone Os
Safari
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.
1Administration Views Project
1Administration Views
May 6, 2026
Sep 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive inform...Show more
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.Show less