← Back
CWE-200

10,406 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sympa
1Sympa
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.
1Cisco
1Unified Communications Manager
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API com...Show more
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.Show less
2Debian
Websvn
2Debian Linux
Websvn
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.
1Emc
2Vipr Srm
Watch4net
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.
2Broadcom
Symantec
2Data Center Security
Symantec Critical System Protection
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated...Show more
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors.Show less
1Ibm
1Api Management
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vectors.
1Cisco
1Webex Meeting Center
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo341...Show more
Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165.Show less
1Ibm
3Serverguide
Toolscenter SuiteUpdatexpress System Packs Installer
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a fil...Show more
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.Show less
1Clorius Controls A/s
1Java Web Client
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.
1Apache
1Cloudstack
May 6, 2026
Jan 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
1Cisco
1Webex Meeting Center
May 6, 2026
Jan 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug ID CSCus18281.
1Mozilla
2Firefox
Seamonkey
May 6, 2026
Jan 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that trigge...Show more
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.Show less
1Siemens
1Simatic Wincc Sm@rtclient
May 6, 2026
Jan 14, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.
1Siemens
1Simatic Wincc Sm@rtclient
May 6, 2026
Jan 14, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.
1Dlink
1Dap 1360 Firmware
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by setting the client_login cookie to admin.
1Maianscriptworld
1Maian Uploader
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an error message.
1Joomlaskin
1Js Multi Hotel
May 6, 2026
Jan 13, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php,...Show more
The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the installation path via a request to (1) functions.php, (2) myCalendar.php, (3) refreshDate.php, (4) show_image.php, (5) widget.php, (6) phpthumb/GdThumb.inc.php, or (7) phpthumb/thumb_plugins/gd_reflection.inc.php in includes/.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Jan 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requ...Show more
The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCuj40247.Show less
1Mcafee
1Epolicy Orchestrator
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge...Show more
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.Show less
1Cisco
1Webex Meetings Server
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The OutlookAction LI in Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive encrypted-password information via unspecified vectors, aka Bug IDs CSCuj40453 and CSCuj40449.