CWE-200
10,400 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,400)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes. |
Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." |
Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API. |
1Qnap 2Photo Station Photo Station FirmwareMay 6, 2026 Jun 9, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php. |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a .. (dot dot) in the "l" parameter, which reveals the i...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx. |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attacke...Show more |
1Ddsn 1Cm3 Acora Content Management System May 6, 2026 Jun 6, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remot...Show more |
3Linux RedhatSuse4Enterprise Linux Enterprise MrgLinux Enterprise Desktop+1 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 3.3 LOW· v2 kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a deni...Show more |
4Fedoraproject FreebsdHp+1 more4Fedora FreebsdHpux+1 moreMay 6, 2026 Jun 4, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered fi...Show more |
The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecifi...Show more |
maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified vectors. |
enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information...Show more |
The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader...Show more |
1Ibm 7Change And Configuration Management Database Maximo Asset ManagementMaximo Service Desk+4 moreMay 6, 2026 May 26, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837 and 7.5.x before 7.5.0.5 IFIX006; SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2; and Tivoli IT Asset Management for IT, Tivoli Se...Show more |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain pot...Show more |
1Ibm 2Maximo Asset Management Smartcloud Control DeskMay 6, 2026 May 26, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 frontcontroller.jsp in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to obtain sensitive information via an inv...Show more |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie...Show more |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information and technical data via a request to a public page. |
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resou...Show more |