← Back
CWE-200

10,415 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,415)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
May 6, 2026
Jun 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempti...Show more
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.Show less
1Moodle
1Moodle
May 6, 2026
Jun 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allow...Show more
message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.Show less
1Moodle
1Moodle
May 6, 2026
Jun 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request...Show more
calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.Show less
1Moodle
1Moodle
May 6, 2026
Jun 1, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with re...Show more
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.Show less
1Blue Coat
4Ssl Visibility Appliance Sv1800 Firmware
Ssl Visibility Appliance Sv2800 FirmwareSsl Visibility Appliance Sv3800 Firmware+1 more
May 6, 2026
May 30, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator's cookie, which...Show more
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not include the HTTPOnly flag in a Set-Cookie header for the administrator's cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, a different vulnerability than CVE-2015-2855.Show less
1Blue Coat
4Ssl Visibility Appliance Sv1800 Firmware
Ssl Visibility Appliance Sv2800 FirmwareSsl Visibility Appliance Sv3800 Firmware+1 more
May 6, 2026
May 30, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator's cookie in an https session, which makes it...Show more
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator's cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, a different vulnerability than CVE-2015-4138.Show less
1Cisco
1Unified Meetingplace
May 6, 2026
May 30, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, r...Show more
The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCus97452.Show less
1Cisco
2Headend Digital Broadband Delivery System
Headend System Release
May 6, 2026
May 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, via a crafted header in an HTTP request, aka Bug ID CSCus44909.
1Arcserve
1Arcserve Unified Data Protection
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method.
1Sap
1Hana
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement, aka SAP Security Note 2109565.
1Cisco
1Identity Services Engine Software
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as dem...Show more
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.Show less
1Ibm
1Websphere Commerce
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.
1Hp
1Network Virtualization
May 6, 2026
May 25, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController compone...Show more
HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569.Show less
1Ibm
1Security Siteprotector System
May 6, 2026
May 25, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.
1Ibm
1Workload Deployer
May 6, 2026
May 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.
1Ibm
1Endpoint Manager Family
May 6, 2026
May 25, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, whi...Show more
The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.Show less
1Ibm
1Infosphere Master Data Management Server
May 6, 2026
May 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary...Show more
The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Huawei
2E355s Mobile Wifi Firmware
Webui
May 6, 2026
May 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configuration information by sniffing the network or sending unspecified comman...Show more
Huawei E355s Mobile WiFi with firmware before 22.158.45.02.625 and WEBUI before 13.100.04.01.625 allows remote attackers to obtain sensitive configuration information by sniffing the network or sending unspecified commands.Show less
1Piriform
1Ccleaner
May 6, 2026
May 20, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Piriform CCleaner 3.26.0.1988 through 5.02.5101 writes the filenames to disk when overwriting files, which allows local users to obtain sensitive information by searching unallocated disk space.
1Ibm
1License Metric Tool
May 6, 2026
May 20, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.