← Back
CWE-200

10,405 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Unified Computing System
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log files, aka Bug ID CSCur99239.
1Logintoboggan Project
1Logintoboggan
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not properly unset the authorized user role for certain users, which allows remote attackers with the pre-authorized role to gain privileges and possibly ob...Show more
The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not properly unset the authorized user role for certain users, which allows remote attackers with the pre-authorized role to gain privileges and possibly obtain sensitive information by accessing a Page Not Found (404) page.Show less
1Mantisbt
1Mantisbt
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the pa...Show more
The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain database credentials via a URL in the hostname parameter and reading the parameters in the response sent to the URL.Show less
1Entrypass
1N5200 Active Network Control Panel
May 6, 2026
Dec 7, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, differe...Show more
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.Show less
1Square Enix Co Ltd
1Kaku San Sei Million Aruthur
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain privileges via a crafted application.
1Lg
3L 03e
L 04dL 09c
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers to obtain sensitive information via unspecified vectors.
1Nagios
1Nagios
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.
1Nagios
1Nagios
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.
1Redhat
1Enterprise Virtualization
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listi...Show more
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.Show less
1Icecast
1Icecast
May 6, 2026
Dec 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors.
1Modx
1Modx Revolution
May 6, 2026
Dec 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access...Show more
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Svnlabs
1Html5 Mp3 Player With Playlist Free
May 6, 2026
Dec 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html5plus/playlist.php.
1Kennziffer
1Ke Questionnaire
May 6, 2026
Dec 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remote attackers to obtain sensitive information via a direct request.
1Gleamtech
1Filevista
May 6, 2026
Dec 2, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
GleamTech FileVista before 6.1 allows remote authenticated users to obtain sensitive information via a crafted path when saving a zip file, which reveals the installation path in an error message.
1Filefield Project
1Filefield
May 6, 2026
Dec 1, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attach...Show more
The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.Show less
1Notify Project
1Notify
May 6, 2026
Dec 1, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fiel...Show more
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.Show less
1Arris
1Vap2500 Firmware
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
1Ibm
3Qradar Risk Manager
Qradar Security Information And Event ManagerQradar Vulnerability Manager
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to...Show more
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.Show less
1Ibm
3Qradar Risk Manager
Qradar Security Information And Event ManagerQradar Vulnerability Manager
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie informati...Show more
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.Show less
1Siemens
4Simatic Pcs7
Simatic Pcs 7Simatic Tiaportal+1 more
May 6, 2026
Nov 26, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers...Show more
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.Show less