← Back
CWE-200

10,404 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,404)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hl7
1C Cda
May 6, 2026
Sep 2, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, lea...Show more
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.Show less
1Iii
1Encore Discovery Solution
May 6, 2026
Aug 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.
1Cisco
1Cloud Portal
May 6, 2026
Aug 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packet...Show more
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, aka Bug IDs CSCuh87398 and CSCuh87380.Show less
1Novell
1Groupwise
May 6, 2026
Aug 29, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.
3Apache
LibreofficeRedhat
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
May 6, 2026
Aug 27, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.
1Ibm
1Websphere Application Server
May 6, 2026
Aug 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.
1Ibm
1Websphere Application Server
May 6, 2026
Aug 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.
2Fedoraproject
Redhat
3389 Directory Server
Directory ServerEnterprise Linux
May 6, 2026
Aug 21, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
1Ibm
1Powervc
May 6, 2026
Aug 20, 2014
N/A· v4
N/A· v3
2.9 LOW· v2
IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, which allows remote attackers to discover credentials by sniffing the network.
1Emc
1Documentum Content Server
May 6, 2026
Aug 20, 2014
N/A· v4
N/A· v3
6.3 MEDIUM· v2
EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to read sensitive object metadata via an RPC command.
3Canonical
OpenstackRedhat
6Neutron
OpenstackOslo+3 more
May 6, 2026
Aug 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authe...Show more
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).Show less
1Cisco
15Nexus 5000
Nexus 5010Nexus 5010p Switch+12 more
May 6, 2026
Aug 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enume...Show more
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.Show less
1Ibm
2Business Process Manager
Websphere Application Server
May 6, 2026
Aug 17, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration i...Show more
callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Ibm
2Global Console Manager 16 Firmware
Global Console Manager 32 Firmware
May 6, 2026
Aug 17, 2014
N/A· v4
N/A· v3
6.3 MEDIUM· v2
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.
1Openssl
1Openssl
May 6, 2026
Aug 13, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when pretty printing is used, does not ensure the presence of '\0' characters, which all...Show more
The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when pretty printing is used, does not ensure the presence of '\0' characters, which allows context-dependent attackers to obtain sensitive information from process stack memory by reading output from X509_name_oneline, X509_name_print_ex, and unspecified other functions.Show less
1Ibm
1Websphere Portal
May 6, 2026
Aug 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whether the intranet host exists, which allows remote attackers to map the...Show more
IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whether the intranet host exists, which allows remote attackers to map the intranet network via a series of requests.Show less
1Ibm
1Business Process Manager
May 6, 2026
Aug 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified JSP diagnostic page.
1Pyplate
1Pyplate
May 6, 2026
Aug 7, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
1Pyplate
1Pyplate
May 6, 2026
Aug 7, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
1Pyplate
1Pyplate
May 6, 2026
Aug 7, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the administrator password by reading this file.