← Back
CWE-200

10,404 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,404)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Digital Editions
May 6, 2026
Oct 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by book-navigati...Show more
Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by book-navigation information.Show less
2Openstack
Redhat
4Cinder
NovaOpenstack+1 more
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local use...Show more
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.Show less
3Canonical
OpenstackRedhat
5Cinder
NovaOpenstack+2 more
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by...Show more
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.Show less
1Openstack
1Cinder
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 h...Show more
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.Show less
1Perl
1Cgi Application Module
May 6, 2026
Oct 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive information (web queries and environment details) via vectors related to the...Show more
The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive information (web queries and environment details) via vectors related to the dump_html function.Show less
1Redhat
1Conga
May 6, 2026
Oct 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.
1Cisco
1Webex Meetings Server
May 6, 2026
Oct 5, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive information by reading logs, aka Bug IDs CSCuq36417 and CSCuq40344.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Oct 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-version information by reading the verbose response data that is provided fo...Show more
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-version information by reading the verbose response data that is provided for a request to an unspecified URL, aka Bug ID CSCuq65542.Show less
3Canonical
OpenstackRedhat
3Keystone
OpenstackUbuntu Linux
May 6, 2026
Oct 2, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated...Show more
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.Show less
1Ibm
12Change And Configuration Management Database
Maximo Asset ManagementMaximo Asset Management Essentials+9 more
May 6, 2026
Oct 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 and 7.2 for T...Show more
IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote attackers to obtain sensitive directory information by reading an unspecified error message.Show less
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.
1Plone
1Plone
May 6, 2026
Sep 30, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.
1Ibm
1Rational Clearcase
May 6, 2026
Sep 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on w...Show more
The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.Show less
1Ibm
1Rational Clearcase
May 6, 2026
Sep 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for the session cookie in an https session, which makes it easier for remote...Show more
The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.Show less
1Bump Project
1Bump
May 6, 2026
Sep 22, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Bump application for Android does not properly handle implicit intents, which allows attackers to obtain sensitive owner-name information via a crafted application.
1Apple
1Mac Os X
May 6, 2026
Sep 19, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The kernel in Apple OS X before 10.9.5 allows local users to obtain sensitive address information and bypass the ASLR protection mechanism by leveraging predictability of the location of the CPU Global Descriptor Table.
1Ibm
1Qradar Security Information And Event Manager
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 does not properly handle SSH connections, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
1Ibm
2Integration Bus
Websphere Message Broker
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page.