← Back
CWE-200

10,413 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,413)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle request headers during processing of redirects in HTTP responses, which allows remote attackers to bypass the...Show more
The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle request headers during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Apple
1Iphone Os
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading...Show more
CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file.Show less
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a craf...Show more
CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Mcafee
1Advanced Threat Defense
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to obtain sensitive configuration information via unspecified vectors.
1Siemens
1Simatic Step 7
May 6, 2026
Apr 6, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) we...Show more
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging the ability to read these files.Show less
1Ibm
1General Parallel File System
May 6, 2026
Apr 6, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included key...Show more
/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.Show less
1Xen
1Xen
May 6, 2026
Apr 5, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
drivers/xen/usbback/usbback.c in linux-2.6.18-xen-3.4.0 (aka the Xen 3.4.x support patches for the Linux kernel 2.6.18), as used in the Linux kernel 2.6.x and 3.x in SUSE Linux distributions, allows guest OS users to obt...Show more
drivers/xen/usbback/usbback.c in linux-2.6.18-xen-3.4.0 (aka the Xen 3.4.x support patches for the Linux kernel 2.6.18), as used in the Linux kernel 2.6.x and 3.x in SUSE Linux distributions, allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory via unspecified vectors.Show less
1Inductiveautomation
1Ignition
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.
1Inductiveautomation
1Ignition
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception, as demonstrated by pathname information.
1Semperfiwebdesign
1All In One Seo Pack
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive...Show more
The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading HTML source code.Show less
1Cisco
1Unified Communications Domain Manager
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via a file-inclusion attack, aka Bug ID CSCup94744.
1Hospira
1Mednet
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password...Show more
Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.Show less
1Hospira
1Mednet
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.
1Sap
1Netweaver
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.
1Mozilla
1Firefox
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote atta...Show more
The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2012-2808.Show less
1Synology
1Diskstation Manager
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial...Show more
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.Show less
1Ibm
2Security Access Manager For Web 7.0 Firmware
Security Access Manager For Web 8.0 Firmware
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to unicast queries with source addresses that are not link-local, which allo...Show more
The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.Show less
1Hp
1Operations Orchestration
May 6, 2026
Mar 31, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Powershell Operations in HP Operations Orchestration 9.x and 10.x allows remote authenticated users to obtain sensitive information via unknown vectors.
2Aveva
Schneider Electric
2Aveva Edge
Wonderware Intouch 2014
May 6, 2026
Mar 29, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obta...Show more
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file.Show less
2Aveva
Schneider Electric
2Aveva Edge
Wonderware Intouch 2014
May 6, 2026
Mar 29, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information...Show more
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.Show less