← Back
CWE-200

10,414 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,414)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Db2
May 6, 2026
May 8, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive in...Show more
IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.Show less
5Apple
CanonicalDebian+2 more
6Curl
Debian LinuxEnterprise Manager Ops Center+3 more
May 6, 2026
May 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the heade...Show more
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.Show less
1Rest Client Project
1Rest Client
May 6, 2026
Apr 29, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.
5Debian
FedoraprojectOpensuse+2 more
9Debian Linux
FedoraLinux Enterprise Desktop+6 more
May 6, 2026
Apr 28, 2015
N/A· v4
N/A· v3
2.9 LOW· v2
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist requ...Show more
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.Show less
1Ibm
1Websphere Application Server
May 6, 2026
Apr 27, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified ve...Show more
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.Show less
1Ibm
8Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Engineering Lifecycle Manager+5 more
May 6, 2026
Apr 27, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2,...Show more
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Engineering Lifecycle Manager 4.0.3 through 4.0.7 and 5.0 through 5.0.2, Rational Rhapsody Design Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, and Rational Software Architect Design Manager 4.0 through 4.0.7 and 5.0 through 5.0.2 allows remote attackers to read JSP source code via a crafted request.Show less
1Django Markupfield Project
1Django Markupfield
May 6, 2026
Apr 24, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and read arbitrary files via unspecified vectors.
1Certify Project
1Certify
May 6, 2026
Apr 22, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information v...Show more
The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and creating) the PDF certificates."Show less
1Path Breadcrumbs Project
1Path Breadcrumbs
May 6, 2026
Apr 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and obtain sensitive node titles by reading a 403 Not Found page.
1Apache
1Tomcat Connectors
May 6, 2026
Apr 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
1Amazon Aws Project
1Amazon Aws
May 6, 2026
Apr 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.
2Debian
Google
2Chrome
Debian Linux
May 6, 2026
Apr 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML documen...Show more
The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote attackers to obtain sensitive information from local files via a crafted (1) http or (2) https web site.Show less
3Canonical
DebianGoogle
3Chrome
Debian LinuxUbuntu Linux
May 6, 2026
Apr 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for...Show more
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.Show less
1Searchblox
1Searchblox
May 6, 2026
Apr 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI.
1Blue Coat
1Malware Analysis Appliance
May 6, 2026
Apr 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access restrictions, and list or read arbitrary documents, by providing matchi...Show more
search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access restrictions, and list or read arbitrary documents, by providing matching keywords in conjunction with a crafted parameter.Show less
1Lenovo
1Usb Enhanced Performance Keyboard
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
1Usaa
1Mobile Banking
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login, which might allow physically proximate users to obtain banking account numbers and...Show more
The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login, which might allow physically proximate users to obtain banking account numbers and balances.Show less
1Hotspotexpress
1Hotex Billing Manager
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
4Adobe
NovellOpensuse+1 more
9Enterprise Linux Desktop Supplementary
Enterprise Linux Server SupplementaryEnterprise Linux Server Supplementary Eus+6 more
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information v...Show more
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.Show less
4Adobe
OpensuseRedhat+1 more
8Enterprise Linux Desktop Supplementary
Enterprise Linux Server SupplementaryEnterprise Linux Server Supplementary Eus+5 more
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass...Show more
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-0357.Show less