← Back
CWE-200

10,406 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pnmsoft
1Sequence Kinetics
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Form Controls CSS file in PNMsoft Sequence Kinetics before 7.7 allows remote attackers to obtain sensitive source-code information via unspecified vectors.
1Ibm
1Flex System Manager
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sensitive information, and consequently gain privileges or conduct impersonation attacks, via unspecifie...Show more
IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sensitive information, and consequently gain privileges or conduct impersonation attacks, via unspecified vectors.Show less
1Mcafee
1Data Loss Prevention Endpoint
May 6, 2026
Feb 17, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to obtain sensitive password information via a crafted URL.
1Rhodecode
1Rhodecode Enterprise
May 6, 2026
Feb 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
2Kallithea Scm
Rhodecode
2Kallithea
Rhodecode Enterprise
May 6, 2026
Feb 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.
1Hp
1Universal Configuration Management Database
May 6, 2026
Feb 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.
1Okb.co.jp
1Smartphone Passbook
May 6, 2026
Feb 15, 2015
N/A· v4
N/A· v3
1.8 LOW· v2
The Ogaki Kyoritsu Bank Smartphone Passbook application 1.0.0 for Android creates a log file containing input data from the user, which allows attackers to obtain sensitive information by reading a file.
1Emc
1Captiva Capture
May 6, 2026
Feb 14, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log file, which allows local users to obtain...Show more
The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log file, which allows local users to obtain sensitive information by reading a file.Show less
1Emc
1Documentum D2
May 6, 2026
Feb 14, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain se...Show more
The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain sensitive information by reading a file.Show less
1Ibm
1Curam Social Program Management
May 6, 2026
Feb 14, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows rem...Show more
Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.Show less
2Opensuse
X.org
2Opensuse
X Server
May 6, 2026
Feb 13, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string leng...Show more
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.Show less
1Redhat
2Jboss Enterprise Application Platform
Jboss Operations Network
May 6, 2026
Feb 13, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain at...Show more
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.Show less
1Ovirt
1Ovirt
May 6, 2026
Feb 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this co...Show more
oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Ibm
1Infosphere Biginsights
May 6, 2026
Feb 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive Alert management-services API information via a network-tracing attack.
1Microsoft
1Internet Explorer
May 6, 2026
Feb 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."
1Microsoft
9Windows 7
Windows 8Windows 8.1+6 more
May 6, 2026
Feb 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize mem...Show more
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process memory via a crafted image file, aka "TIFF Processing Information Disclosure Vulnerability."Show less
1Cloudera
1Cloudera Manager
May 6, 2026
Feb 10, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.
1Cisco
1Unified Ip Phones 9900 Series Firmware
May 6, 2026
Feb 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117.
1Netapp
1Oncommand Balance
May 6, 2026
Feb 6, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related to cleartext storage.
1Ansible
1Tower
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.