CWE-200
10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
pioctls in OpenAFS 1.6.x before 1.6.13 allows local users to read kernel memory via crafted commands. |
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network. |
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by rea...Show more |
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the...Show more |
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via...Show more |
The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS commands, via a crafted HTML document. |
Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session. |
Mozilla Firefox OS before 2.2 does not require the wifi-manage privilege for reading a Wi-Fi system message, which allows attackers to obtain potentially sensitive information via a crafted app. |
1Ibm 1Websphere Datapower Xc10 Appliance Firmware May 6, 2026 Aug 3, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and...Show more |
1Siemens 2Simatic Wincc Sm@rtclient Simatic Wincc Sm@rtclient LiteMay 6, 2026 Aug 3, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unsp...Show more |
1Cisco 1Unified Communications Manager May 6, 2026 Aug 1, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated users to discover root credentials via a direct request to an unspecified URL, aka Bug ID C...Show more |
1Symantec 1Endpoint Protection Manager May 6, 2026 Aug 1, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via unknown vectors. |
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive...Show more |
3Fedoraproject OpensuseRubyonrails4Fedora Jquery RailsJquery Ujs+1 moreMay 6, 2026 Jul 26, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transm...Show more |
Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection mechanism and obtain sensitive information via a crafted application. |
1Emc 2Avamar Server Avamar Server Virtual EditionMay 6, 2026 Jul 23, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using the Avamar Desktop/Laptop client interfa...Show more |
4Debian GoogleOpensuse+1 more7Chrome Debian LinuxEnterprise Linux Desktop Supplementary+4 moreMay 6, 2026 Jul 23, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for r...Show more |
The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers' installations, which makes it easier for remote authenticated users t...Show more |
1Ibm 1Infosphere Master Data Management May 6, 2026 Jul 20, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified...Show more |
1Ibm 1Infosphere Master Data Management May 6, 2026 Jul 20, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path...Show more |