CWE-200
10,405 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,405)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ekahau 4Activator B4 Staff Badge TagB4 Staff Badge Tag Firmware+1 moreMay 6, 2026 Dec 19, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 uses part of the MAC address as part of the RC4 setup key, which makes it easier for remote att...Show more |
Puppet Enterprise before 3.7.1 allows remote authenticated users to obtain licensing and certificate signing request information by leveraging access to an unspecified API endpoint. |
IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL. |
1Ibm 2Security Access Manager For Mobile Security Access Manager For WebMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive information by sniffing the network during...Show more |
1Ibm 2Security Access Manager For Mobile Security Access Manager For WebMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure that HTTPS is used, which allows remote attackers to obtain sensitive i...Show more |
1Ibm 2Security Access Manager For Mobile Security Access Manager For WebMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to obtain sensitive cookie information by sniffing the network...Show more |
The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive information via a (1) mc_project_get_users, (2) mc_issue_get, (3) mc_filter_ge...Show more |
Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain sensitive information by reading database entries, aka ZEN-15416. |
Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this...Show more |
Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role information by visiting the ZenUsers (aka User Manager) page, aka ZEN-15389. |
Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name and then reading a stack trace, as demonstrated by internal URL informat...Show more |
1Ibm 1Websphere Datapower Xc10 Appliance Firmware May 6, 2026 Dec 12, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors. |
1Ibm 1Websphere Datapower Xc10 Appliance Firmware May 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response. |
AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direct object reference. |
1Ibm 3Operational Decision Manager Websphere Ilog JrulesWebsphere Operational Decision ManagementMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Decision Management 7.5 before FP3 IF41; and Operational Decision Manager 8...Show more |
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreMay 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does...Show more |
Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to obtain sensitive information via unspecified vectors. |
3Adobe AppleMicrosoft4Acrobat Acrobat ReaderMac Os X+1 moreMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, rela...Show more |
3Adobe AppleMicrosoft4Acrobat Acrobat ReaderMac Os X+1 moreMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability th...Show more |
3Adobe AppleMicrosoft4Acrobat Acrobat ReaderMac Os X+1 moreMay 6, 2026 Dec 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability th...Show more |