← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Universal Configuration Management Database
May 6, 2026
Sep 16, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.
1Hp
1Arcsight Logger
May 6, 2026
Sep 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.
1Ibm
1Websphere Commerce
May 6, 2026
Sep 14, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors.
1Phpmyadmin
1Phpmyadmin
May 6, 2026
Sep 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credenti...Show more
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.Show less
1Microsoft
1Exchange Server
May 6, 2026
Sep 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace information via a crafted request, aka "Exchange Information Disclosure...Show more
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace information via a crafted request, aka "Exchange Information Disclosure Vulnerability."Show less
1Microsoft
1Internet Explorer
May 6, 2026
Sep 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Information Disclosure Vulnerability."
1Cisco
1Telepresence System Software Ix
May 6, 2026
Sep 5, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which allows remote attackers to obtain cleartext versions of HTTPS traffic o...Show more
Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which allows remote attackers to obtain cleartext versions of HTTPS traffic or spoof devices via a direct request to the certificate directory, aka Bug ID CSCuu63501.Show less
1Fortinet
1Forticlient
May 6, 2026
Sep 3, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.
2Canonical
Mediawiki
2Mediawiki
Ubuntu Linux
May 6, 2026
Sep 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
1Mediawiki
1Mediawiki
May 6, 2026
Sep 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.
1Basware
1Banking
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from...Show more
Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to different vulnerability types. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6746.Show less
1Basware
1Banking
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was...Show more
Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to different vulnerability types.Show less
1Basware
1Banking
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other se...Show more
Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream.Show less
1Linux
1Linux Kernel
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap data structure, which allows local users to obtain sensitive information from kernel memory via a GET_...Show more
The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap data structure, which allows local users to obtain sensitive information from kernel memory via a GET_BITMAP_FILE ioctl call.Show less
1Hp
1Matrix Operating Environment
May 6, 2026
Aug 27, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors.
1Hp
1Systems Insight Manager
May 6, 2026
Aug 27, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a diff...Show more
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-2139.Show less
1Hp
1Systems Insight Manager
May 6, 2026
Aug 27, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a diff...Show more
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5403.Show less
1Hp
1Version Control Repository Manager
May 6, 2026
Aug 26, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Cisco
1Telepresence Video Communication Server Software
May 6, 2026
Aug 26, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA)...Show more
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, aka Bug ID CSCuv78531.Show less
1Sgi
1Xfsprogs
May 6, 2026
Aug 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading a generated image.