← Back
CWE-200

10,405 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Manageengine
1Oputils
May 6, 2026
Nov 25, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile."
1Moodle
1Moodle
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.
1Moodle
1Moodle
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain s...Show more
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.Show less
1Moodle
1Moodle
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive informati...Show more
lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.Show less
1Directwebremoting
1Direct Web Remoting
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data...Show more
The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Oracle
1Database Server
May 6, 2026
Nov 23, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a diff...Show more
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4293, CVE-2014-4296, CVE-2014-4297, CVE-2014-4310, and CVE-2014-6547. NOTE: this issue was originally mapped to CVE-2014-4301, but CVE-2014-4301 is for an unrelated vulnerability.Show less
1Tibco
3Silver Fabric Enabler
Spotfire Deployment KitSpotfire Web Player
May 6, 2026
Nov 21, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player befo...Show more
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.Show less
1Commerceguys
1Commerce
May 6, 2026
Nov 20, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new accounts created at checkout, which allows...Show more
The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new accounts created at checkout, which allows remote attackers to obtain sensitive information via unspecified vectors.Show less
1Arubanetworks
1Clearpass
May 6, 2026
Nov 19, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unspecified vectors.
1Arubanetworks
1Clearpass
May 6, 2026
Nov 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.
1Arubanetworks
1Clearpass
May 6, 2026
Nov 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which allows remote attackers to obtain version numbers, module configuration,...Show more
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which allows remote attackers to obtain version numbers, module configuration, and other sensitive information by reading the page.Show less
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Nov 18, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain se...Show more
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.Show less
1Apple
1Mac Os X
May 6, 2026
Nov 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vec...Show more
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.Show less
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Nov 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive inform...Show more
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.Show less
1Cisco
1Ios
May 6, 2026
Nov 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.
1Ibm
1Security Identity Manager
May 6, 2026
Nov 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.
1Redhat
1Jboss Enterprise Application Platform
May 6, 2026
Nov 17, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this f...Show more
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.Show less
1Webfs
1Webfs
May 6, 2026
Nov 16, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by reading the file.
1Bestpractical
1Request Tracker
May 6, 2026
Nov 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows re...Show more
The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows remote attackers to reuse unauthorized sessions and obtain user preferences and caches via unspecified vectors.Show less
2Oracle
Uninett
2Linux
Mod Auth Mellon
May 6, 2026
Nov 15, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "session...Show more
The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."Show less