← Back
CWE-200

10,414 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,414)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Flash Player
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass...Show more
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3040.Show less
1Fortinet
1Fortimail
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.
2Fedoraproject
Wesnoth
2Battle For Wesnoth
Fedora
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file.
1Mediawiki
1Mediawiki
May 6, 2026
Apr 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file,...Show more
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."Show less
1Freebsd
1Freebsd
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive...Show more
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file.Show less
1Apple
1Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sensitive information by reading this file.
1Apple
1Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by snif...Show more
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.Show less
1Apple
1Safari
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history information via vectors involving push-notification requests.
1Apple
1Safari
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by r...Show more
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries.Show less
1Apple
1Iphone Os
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The UIKit View component in Apple iOS before 8.3 displays unblurred application snapshots in the Task Switcher, which makes it easier for physically proximate attackers to obtain sensitive information by reading the devi...Show more
The UIKit View component in Apple iOS before 8.3 displays unblurred application snapshots in the Task Switcher, which makes it easier for physically proximate attackers to obtain sensitive information by reading the device screen.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
The Sandbox Profiles component in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to discover hardware identifiers via a crafted app.
1Apple
1Iphone Os
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
The Sandbox Profiles component in Apple iOS before 8.3 allows attackers to read the (1) telephone number or (2) e-mail address of a recent contact via a crafted app.
1Apple
2Iphone Os
Safari
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-history data from the history.plist file, which allows attackers to obta...Show more
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-history data from the history.plist file, which allows attackers to obtain sensitive information by reading this file.Show less
1Apple
1Iphone Os
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain sensitive information by reading a history file.
1Apple
2Iphone Os
Tvos
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-download request data.
1Apple
1Iphone Os
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.
1Apple
1Iphone Os
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making man...Show more
The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.Show less
1Apple
1Iphone Os
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.
1Apple
2Iphone Os
Tvos
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
IOMobileFramebuffer in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.
1Apple
3Iphone Os
Mac Os XTvos
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.