CWE-200
10,414 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,414)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive in...Show more |
5Apple CanonicalDebian+2 more6Curl Debian LinuxEnterprise Manager Ops Center+3 moreMay 6, 2026 May 1, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the heade...Show more |
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. |
5Debian FedoraprojectOpensuse+2 more9Debian Linux FedoraLinux Enterprise Desktop+6 moreMay 6, 2026 Apr 28, 2015 N/A· v4 N/A· v3 2.9 LOW· v2 Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist requ...Show more |
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified ve...Show more |
1Ibm 8Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 moreMay 6, 2026 Apr 27, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2,...Show more |
1Django Markupfield Project 1Django Markupfield May 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and read arbitrary files via unspecified vectors. |
The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information v...Show more |
1Path Breadcrumbs Project 1Path Breadcrumbs May 6, 2026 Apr 21, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and obtain sensitive node titles by reading a 403 Not Found page. |
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors. |
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL. |
The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML documen...Show more |
3Canonical DebianGoogle3Chrome Debian LinuxUbuntu LinuxMay 6, 2026 Apr 19, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for...Show more |
SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI. |
1Blue Coat 1Malware Analysis Appliance May 6, 2026 Apr 17, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access restrictions, and list or read arbitrary documents, by providing matchi...Show more |
1Lenovo 1Usb Enhanced Performance Keyboard May 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output. |
The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login, which might allow physically proximate users to obtain banking account numbers and...Show more |
1Hotspotexpress 1Hotex Billing Manager May 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. |
4Adobe NovellOpensuse+1 more9Enterprise Linux Desktop Supplementary Enterprise Linux Server SupplementaryEnterprise Linux Server Supplementary Eus+6 moreMay 6, 2026 Apr 14, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information v...Show more |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Supplementary Enterprise Linux Server SupplementaryEnterprise Linux Server Supplementary Eus+5 moreMay 6, 2026 Apr 14, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass...Show more |