← Back
CWE-200

10,413 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,413)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Aveva
Schneider Electric
2Aveva Edge
Wonderware Intouch 2014
May 6, 2026
Mar 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote...Show more
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.Show less
2Aveva
Schneider Electric
2Aveva Edge
Wonderware Intouch 2014
May 6, 2026
Mar 29, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Con...Show more
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.Show less
1Johnsoncontrols
1Metsys
May 6, 2026
Mar 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network...Show more
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.Show less
1Cisco
1Unified Callmanager
May 6, 2026
Mar 28, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.
1Websense
2Triton Ap Email
V Series Appliances
May 6, 2026
Mar 27, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.
1Websense
1Triton Ap Web
May 6, 2026
Mar 27, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication.
5Debian
FedoraprojectOpensuse+2 more
5Debian Linux
FedoraOpensuse+2 more
May 6, 2026
Mar 27, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory...Show more
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.Show less
1Websense
1V Series Appliances
May 6, 2026
Mar 27, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to read arbitrary files and obtain passwords via a crafted path.
1Websense
4Triton Ap Data
Triton Ap EmailTriton Ap Web+1 more
May 6, 2026
Mar 26, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or...Show more
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or the (2) Explorer configuration (websense.ini) file.Show less
1Cisco
1Mobility Services Engine
May 6, 2026
Mar 26, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bug ID CSCut24792.
1Ibm
2Security Identity Manager Active Directory Adapter
Tivoli Identity Manager Active Directory Adapter
May 6, 2026
Mar 25, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and t...Show more
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file.Show less
1Ibm
2Installation Manager
Rational Clearcase
May 6, 2026
Mar 25, 2015
N/A· v4
N/A· v3
1.2 LOW· v2
IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which mig...Show more
IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation account.Show less
1Emc
1Documentum Xcelerated Management System
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
EMC Documentum xCelerated Management System (xMS) 1.1 before P14 stores cleartext Windows Service credentials in a batch file during Documentum Platform and xCelerated Composition Platform (xCP) provisioning, which allow...Show more
EMC Documentum xCelerated Management System (xMS) 1.1 before P14 stores cleartext Windows Service credentials in a batch file during Documentum Platform and xCelerated Composition Platform (xCP) provisioning, which allows local users to obtain sensitive information by reading a file.Show less
1Ibm
1Powervc
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by...Show more
powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process.Show less
1Mybb
1Mybb
May 6, 2026
Mar 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.
1Ibm
1Liberty
May 6, 2026
Mar 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Java overlay feature in IBM Bluemix Liberty before 1.13-20150209-1122 for Java does not properly support WAR applications, which allows remote attackers to obtain sensitive information via unspecified vectors.
1Ibm
5Rational Collaborative Lifecycle Management
Rational Doors Next GenerationRational Quality Manager+2 more
May 6, 2026
Mar 18, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before...Show more
IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to read the dashboards of arbitrary users via unspecified vectors.Show less
3Debian
FedoraprojectXen
3Debian Linux
FedoraXen
May 6, 2026
Mar 12, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.
1Xen
1Xen
May 6, 2026
Mar 12, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported acce...Show more
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.Show less
1Apple
1Iphone Os
May 6, 2026
Mar 12, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended activation requirement and read the home screen by leveraging an application crash during the activation process.