CWE-200
10,393 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,393)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call. |
Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows attackers to read the clipboard via unspecified vectors. |
1Microsoft 10Windows 7 Windows 8Windows 8.1+7 moreMay 6, 2026 Mar 12, 2014 N/A· v4 N/A· v3 6.6 MEDIUM· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a...Show more |
The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in...Show more |
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file wi...Show more |
The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remote attackers to obtain access via a VPN session. |
2Canonical Debian2Advanced Package Tool Ubuntu LinuxApr 29, 2026 Mar 1, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecif...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet da...Show more |
1Cisco 1Unified Contact Center Express Editor Software Apr 29, 2026 Feb 27, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The disaster recovery system (DRS) in Cisco Unified Contact Center Express (Unified CCX) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCu...Show more |
1Microsoft 1Internet Explorer Apr 22, 2026 Feb 26, 2014 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by exami...Show more |
3Apache DebianOracle3Debian Linux SolarisTomcatApr 29, 2026 Feb 26, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml,...Show more |
The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, processes POST requests by using the body of a redirecting page instead of the...Show more |
The libxml RSHUTDOWN function in PHP 5.x allows remote attackers to bypass the open_basedir protection mechanism and read arbitrary files via vectors involving a stream_close method call during use of a custom stream wra...Show more |
The do_devinfo_ioctl function in drivers/staging/comedi/comedi_fops.c in the Linux kernel before 3.1 allows local users to obtain sensitive information from kernel memory via a copy of a short string. |
1Sap 1Customer Relationship Management Apr 29, 2026 Feb 14, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue. |
2Internet2 Shibboleth2Opensaml OpensamlApr 29, 2026 Feb 14, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to con...Show more |
Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability." |
1Microsoft 10Windows 7 Windows 8Windows 8.1+7 moreApr 29, 2026 Feb 12, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Se...Show more |
1Visibility Software 1Cyber Recruiter Apr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote atta...Show more |