← Back
CWE-200

10,405 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,405)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Epicor
1Epicor Enterprise
May 6, 2026
Nov 4, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by reading HTML source code of the database connection and email settings pag...Show more
Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by reading HTML source code of the database connection and email settings page.Show less
1Plone
1Plone
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2...Show more
The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.Show less
5Canonical
DebianOpensuse+2 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+9 more
May 6, 2026
Nov 1, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
1Linksys
20E4200v2
E4200v2 FirmwareEa2700+17 more
May 6, 2026
Nov 1, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and...Show more
Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain sensitive information or modify data via a JNAP action in a JNAP/ HTTP request.Show less
1Testlink
1Testlink
May 6, 2026
Oct 31, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information by reading a Java stack trace.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive informati...Show more
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remote attackers to obtain sensitive information via unspecified vectors.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network ports.
1Pidgin
1Pidgin
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from process memory via a crafted XMPP message.
1Ibm
1Websphere Portal
May 6, 2026
Oct 28, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requ...Show more
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows remote attackers to determine the validity of filenames via a series of requests.Show less
1Robert Ancell
1Lightdm
May 6, 2026
Oct 27, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
lightdm before 1.0.9 does not properly close file descriptors before opening a child process, which allows local users to write to the lightdm log or have other unspecified impact.
1Ibm
1Security Appscan Source
May 6, 2026
Oct 26, 2014
N/A· v4
N/A· v3
1.8 LOW· v2
The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port.
2Emc
Meditech
2Meditech
Networker
May 6, 2026
Oct 25, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local use...Show more
The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.Show less
1Ibm
1Classic Meeting Server
May 6, 2026
Oct 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading an exported Record and Playback (RAP) file.
1Dokuwiki
1Dokuwiki
May 6, 2026
Oct 22, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.
1Dokuwiki
1Dokuwiki
May 6, 2026
Oct 22, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.