← Back
CWE-200

10,400 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,400)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
May 6, 2026
May 21, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-we...Show more
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.Show less
1Cisco
6Webex Business Suite
Webex Event CenterWebex Meeting Center+3 more
May 6, 2026
May 20, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and earlier, and WebEx Business Suite (WBS) 27 before 27.32.31.16, 28 before...Show more
meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and earlier, and WebEx Business Suite (WBS) 27 before 27.32.31.16, 28 before 28.12.13.18, and 29 before 29.5.1.12 allows remote attackers to obtain sensitive meeting information by leveraging knowledge of a meeting identifier, aka Bug IDs CSCuo68624 and CSCue46738.Show less
1Sap
1Netweaver
May 6, 2026
May 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.
1Microsoft
1Office
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerabil...Show more
Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."Show less
1Adobe
2Acrobat
Acrobat Reader
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X do not properly implement JavaScript APIs, which allows remote attackers to obtain sensitive information via a crafted PDF document...Show more
Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X do not properly implement JavaScript APIs, which allows remote attackers to obtain sensitive information via a crafted PDF document.Show less
1Redhat
2Icedtea Web
Icedtea6
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path...Show more
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.Show less
1Makina Corpus
1Soappy
May 6, 2026
May 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
1Bscw
1Bscw
May 6, 2026
May 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.
1Mediawiki
1Mediawiki
May 6, 2026
May 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) log API, (2) enhanced RecentChanges, and (3) user watchlists.
5Debian
LinuxOracle+2 more
8Debian Linux
Enterprise Linux EusLinux+5 more
May 6, 2026
May 11, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obt...Show more
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.Show less
1Ibm
1Operational Decision Manager
May 6, 2026
May 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does not send appropriate Cache-Control HTTP headers, which allows remote atta...Show more
The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does not send appropriate Cache-Control HTTP headers, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.Show less
1Openstack
1Compute
May 6, 2026
May 8, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read cer...Show more
The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.Show less
1Theforeman
1Foreman
May 6, 2026
May 8, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
1Amtelco
1Misecuremessages
May 6, 2026
May 6, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
1Plone
1Plone
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.
1Ibm
1Websphere Application Server
May 6, 2026
May 1, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.
1Ibm
1Websphere Application Server
May 6, 2026
May 1, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.
1Ibm
1Websphere Application Server
May 6, 2026
May 1, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.
1Ecava
1Integraxor
May 6, 2026
May 1, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.
1Sap
1Netweaver Software Lifecycle Manager
May 6, 2026
Apr 30, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted request, related to SAP Solution Manager 7.1.