← Back
CWE-200

10,406 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Openstack
May 6, 2026
Mar 10, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
1Fedoraproject
2389 Directory Server
Fedora
May 6, 2026
Mar 10, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obta...Show more
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.Show less
1Fedoraproject
2389 Directory Server
Fedora
May 6, 2026
Mar 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via...Show more
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.Show less
2Fedoraproject
Phpmyadmin
2Fedora
Phpmyadmin
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may b...Show more
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.Show less
3Bestpractical
DebianFedoraproject
3Debian Linux
FedoraRequest Tracker
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
1Siemens
1Spcanywhere
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Siemens SPCanywhere application for Android does not properly store application passwords, which allows physically proximate attackers to obtain sensitive information by examining the device filesystem.
1Siemens
1Spcanywhere
May 6, 2026
Mar 7, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of system ID to IP address mappings, which allows man-in-the-middle attackers to discover alarm IP addresses and spoof server...Show more
The Siemens SPCanywhere application for Android and iOS does not use encryption during lookups of system ID to IP address mappings, which allows man-in-the-middle attackers to discover alarm IP addresses and spoof servers by intercepting the client-server data stream.Show less
1Netcat
1Netcat
May 6, 2026
Mar 5, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
1Dlguard
1Dlguard
May 6, 2026
Mar 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
1Ibm
1Notes Traveler Companion
May 6, 2026
Mar 2, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuratio...Show more
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message.Show less
1Sap
1Businessobjects Edge
May 6, 2026
Feb 27, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note 2011395.
3Canonical
MozillaOpensuse
3Firefox
OpensuseUbuntu Linux
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials...Show more
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
May 6, 2026
Feb 25, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.
1Komodia
1Redirector Sdk
May 6, 2026
Feb 24, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other product...Show more
The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, uses the same X.509 certificate private key for a root CA certificate across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging knowledge of this key, as originally reported for Superfish VisualDiscovery on certain Lenovo Notebook laptop products.Show less
1Ibm
1Rational Insight
May 6, 2026
Feb 24, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a crafted request to a Jazz Reporting Service (JRS) report URL.
1Ibm
1Tivoli Storage Manager
May 6, 2026
Feb 24, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows local users to discover the backup/restore encryption-key password via unspecified vectors.
1Kony
1Enterprise Mobile Management
May 6, 2026
Feb 24, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) arbitrary messages via the messageId parameter to selfservice/managedevice/getMessageBody or (2) req...Show more
Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) arbitrary messages via the messageId parameter to selfservice/managedevice/getMessageBody or (2) requests via the requestId parameter to selfservice/devicemgmt/getDeviceInfoTab.htm.Show less
2Puppet
Puppetlabs
2Facter
Facter
May 6, 2026
Feb 23, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.
1Cisco
1Web Security Appliance
May 6, 2026
Feb 20, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP method, aka Bug ID CSCus79174.
1Mit
1Kerberos 5
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients...Show more
The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 transmits uninitialized interposer data to clients, which allows remote attackers to obtain sensitive information from process heap memory by sniffing the network for data in a handle field.Show less