← Back
CWE-200

10,406 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Owncloud
1Owncloud Server
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.
1Owncloud
1Owncloud Server
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information...Show more
Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack.Show less
1Owncloud
1Owncloud
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login, which allows remote attackers to obtain sensitive information by sniffing the network.
1Manageengine
1Servicedesk Plus
May 6, 2026
Feb 4, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf...Show more
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.Show less
1Fortinet
1Fortiauthenticator
May 6, 2026
Feb 3, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command.
1Fortinet
1Fortiauthenticator
May 6, 2026
Feb 3, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.
1Voxpupuli
1Rabbitmq
May 6, 2026
Feb 3, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local users to obtain sensitive information as demonstrated by using Facter.
1Siemens
1Ruggedcom Firmware
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4...Show more
Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allow context-dependent attackers to discover password hashes by reading (1) files or (2) security logs.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
1Cisco
1Webex Meetings Server
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079.
1Ibm
2Integration Bus
Websphere Message Broker
May 6, 2026
Feb 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.
1Apple
1Mac Os X
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e...Show more
Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's URL.Show less
1Apple
1Mac Os X
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, which allows local users to obtain sensitive information by reading a file.
1Apple
1Mac Os X
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, which allows local users to obtain sensitive information by reading from this drive.
1Apple
1Mac Os X
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file.
1Apple
3Iphone Os
Mac Os XTvos
May 6, 2026
Jan 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addresses within an OSBundleMachOHeaders key in a response, which makes it e...Show more
The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addresses within an OSBundleMachOHeaders key in a response, which makes it easier for attackers to bypass the ASLR protection mechanism via a crafted app.Show less
3Canonical
MageiaRedhat
7Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+4 more
May 6, 2026
Jan 29, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDo...Show more
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.Show less
1Kde
2Kde Workspace
Plasma Workspace
May 6, 2026
Jan 26, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
1Adobe
1Flash Player
Apr 21, 2026
Jan 23, 2015
N/A· v4
7.8 HIGH· v3
10.0 HIGH· v2
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass...Show more
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.Show less