← Back
CWE-200

10,417 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Websphere Portal
May 6, 2026
Jul 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.
1Cisco
1Mobility Services Engine
May 6, 2026
Jul 10, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.
1Hospira
1Lifecare Pcainfusion Firmware
May 6, 2026
Jul 6, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
1Samsung
1S Beam
May 6, 2026
Jul 6, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
Samsung SBeam allows remote attackers to read arbitrary images by leveraging an NFC connection to access the HTTP server on port 15000.
2Mozilla
Oracle
2Firefox
Solaris
May 6, 2026
Jul 6, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream...Show more
Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.Show less
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The kernel in Apple iOS before 8.4 and OS X before 10.10.4 does not properly handle HFS parameters, which allows attackers to obtain sensitive memory-layout information via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, which allows attackers to obtain sensitive memory-layout information via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The NTFS implementation in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The LZVN compression feature in AppleFSCompression in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
AppleGraphicsControl in Apple OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information via a crafted app.
1Ibm
1Java
May 6, 2026
Jul 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the J...Show more
IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.Show less
2Cryptopp
Opensuse
2Crypto++ Library
Opensuse
May 6, 2026
Jul 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain...Show more
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.Show less
1Ibm
1Websphere Mq
May 6, 2026
Jul 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which...Show more
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.Show less
1Ibm
1Maximo Asset Management
May 6, 2026
Jul 1, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitiv...Show more
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.Show less
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified port.
1Cisco
1Unified Communications Domain Manager
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589.
1Ibm
1Tivoli Directory Server
May 6, 2026
Jun 28, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log infor...Show more
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log information via a crafted POST request.Show less
1Ibm
1Infosphere Information Server
May 6, 2026
Jun 28, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands.
1Cisco
3Content Security Management Virtual Appliance
Email Security Virtual ApplianceWeb Security Virtual Appliance
May 6, 2026
Jun 26, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH hos...Show more
The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual Appliance (SMAv) devices before 2015-06-25 uses the same default SSH host keys across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a private key from another installation, aka Bug IDs CSCus29681, CSCuu95676, and CSCuu96601.Show less