← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openafs
1Openafs
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
pioctls in OpenAFS 1.6.x before 1.6.13 allows local users to read kernel memory via crafted commands.
1Openafs
1Openafs
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
2Apache
Apple
2Subversion
Xcode
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by rea...Show more
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.Show less
2Apache
Apple
2Subversion
Xcode
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the...Show more
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.Show less
1Jabberd2
1Jabberd2
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via...Show more
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.Show less
1Yodobashi
1Yodobashi
May 6, 2026
Aug 8, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS commands, via a crafted HTML document.
1Sierrawireless
1Aleos
May 6, 2026
Aug 8, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.
1Mozilla
1Firefox Os
May 6, 2026
Aug 8, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox OS before 2.2 does not require the wifi-manage privilege for reading a Wi-Fi system message, which allows attackers to obtain potentially sensitive information via a crafted app.
1Ibm
1Websphere Datapower Xc10 Appliance Firmware
May 6, 2026
Aug 3, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and...Show more
The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere.Show less
1Siemens
2Simatic Wincc Sm@rtclient
Simatic Wincc Sm@rtclient Lite
May 6, 2026
Aug 3, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unsp...Show more
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors.Show less
1Cisco
1Unified Communications Manager
May 6, 2026
Aug 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated users to discover root credentials via a direct request to an unspecified URL, aka Bug ID C...Show more
The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated users to discover root credentials via a direct request to an unspecified URL, aka Bug ID CSCuv21819.Show less
1Symantec
1Endpoint Protection Manager
May 6, 2026
Aug 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via unknown vectors.
2Indusoft
Wonderware
2Intouch
Web Studio
May 6, 2026
Aug 1, 2015
N/A· v4
N/A· v3
1.7 LOW· v2
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive...Show more
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.Show less
3Fedoraproject
OpensuseRubyonrails
4Fedora
Jquery RailsJquery Ujs+1 more
May 6, 2026
Jul 26, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transm...Show more
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value.Show less
1Ibm
1Maximo Anywhere
May 6, 2026
Jul 26, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection mechanism and obtain sensitive information via a crafted application.
1Emc
2Avamar Server
Avamar Server Virtual Edition
May 6, 2026
Jul 23, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interfa...Show more
Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interface to send crafted parameters.Show less
4Debian
GoogleOpensuse+1 more
7Chrome
Debian LinuxEnterprise Linux Desktop Supplementary+4 more
May 6, 2026
Jul 23, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for r...Show more
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.Show less
1Solarwinds
1N Able N Central
May 6, 2026
Jul 21, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers' installations, which makes it easier for remote authenticated users t...Show more
The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers' installations, which makes it easier for remote authenticated users to obtain the cleartext domain-administrator password by locating the encrypted password within HTML source code and then leveraging knowledge of this key from another installation.Show less
1Ibm
1Infosphere Master Data Management
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified...Show more
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.Show less
1Ibm
1Infosphere Master Data Management
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path...Show more
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.Show less