← Back
CWE-200

10,404 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,404)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebKit in Apple iOS before 8 makes it easier for remote attackers to track users during private browsing via a crafted web site that reads HTML5 application-cache data that had been stored during normal browsing.
1Apple
3Iphone Os
Mac Os XTvos
May 6, 2026
Sep 18, 2014
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which allows attackers to obtain sensitive memory-content information via an application that makes crafted IOKit function cal...Show more
IOKit in Apple iOS before 8 and Apple TV before 7 does not properly initialize kernel memory, which allows attackers to obtain sensitive memory-content information via an application that makes crafted IOKit function calls.Show less
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to obtain sensitive Apple ID information via a crafted app.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, which allows attackers to determine the frontmost app by leveraging access to a crafted background app...Show more
The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, which allows attackers to determine the frontmost app by leveraging access to a crafted background app.Show less
1Apple
2Iphone Os
Tvos
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which allows physically proximate attackers to obtain sensitive information by reading this screen.
1Ibm
2Storwize Unified V7000
Storwize V7000 Unified Software
May 6, 2026
Sep 15, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log fi...Show more
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.Show less
1Ecava
1Integraxor
May 6, 2026
Sep 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.
1Mpay24 Project
1Mpay24
May 6, 2026
Sep 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.
1Ibm
7Rational Doors Next Generation
Rational Engineering Lifecycle ManagerRational Quality Manager+4 more
May 6, 2026
Sep 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secu...Show more
IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, and 5.x before 5.0.1; and other Rational products, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.Show less
1Ibm
1Rational License Key Server
May 6, 2026
Sep 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers t...Show more
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.Show less
1Ovirt
1Ovirt
May 6, 2026
Sep 8, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.
1Arris
2Touchstone Dg950a
Touchstone Dg950a Software
May 6, 2026
Sep 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
1Netmaster
2Cbw700 Software
Netmaster Cbw700n
May 6, 2026
Sep 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Netmaster CBW700N cable modem with software 81.447.392110.729.024 has an SNMP community of public, which allows remote attackers to obtain sensitive credential, key, and SSID information via an SNMP request.
1Eucalyptus
1Eucalyptus
May 6, 2026
Sep 5, 2014
N/A· v4
N/A· v3
1.9 LOW· v2
The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading...Show more
The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.Show less
1Manageengine
1Device Expert
May 6, 2026
Sep 4, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
1Ibm
1Db2
May 6, 2026
Sep 4, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.
1Mcafee
1Web Gateway
May 6, 2026
Sep 2, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 allows remote authenticated users to obtain the hashed user passwords via unspecified vectors.
1Iii
1Sierra
May 6, 2026
Sep 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a ser...Show more
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.Show less
1Labanquepostale
1Labanquepostale
May 6, 2026
Sep 2, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via cr...Show more
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.Show less