← Back
CWE-200

10,385 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,385)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Spss Collaboration And Deployment Services
Apr 29, 2026
Feb 1, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.
1Citrix
1Gotomeeting
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application th...Show more
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application that reads the system log file.Show less
1Tntnet
1Tntnet
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \n instead of \r\n, which prevents a null terminator from being added and...Show more
framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \n instead of \r\n, which prevents a null terminator from being added and causes Tntnet to include headers from other requests.Show less
1Openstack
1Swift
Apr 29, 2026
Jan 23, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack...Show more
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.Show less
1Redhat
1Jboss Seam 2 Framework
Apr 29, 2026
Jan 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss We...Show more
Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.Show less
1Fenrir Inc
1Sleipnir Mobile
Apr 29, 2026
Jan 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers t...Show more
The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers to obtain sensitive location information via a web site that makes API calls.Show less
1Doug Poulin
1Command School Student Management System
Apr 29, 2026
Jan 22, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request.
1Linux Nfs
1Nfs Utils
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
3.2 LOW· v2
rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.
1Kernel
1Util Linux
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempt...Show more
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.Show less
1F5
1Big Ip Configuration Utility
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML fil...Show more
XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file.Show less
1Ibm
1Websphere Application Server
Apr 29, 2026
Jan 16, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Opensuse
1Opensuse
Apr 29, 2026
Jan 11, 2014
N/A· v4
N/A· v3
4.4 MEDIUM· v2
The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and po...Show more
The image creation configuration in aaa_base before 16.26.1 for openSUSE 13.1 KDE adds the root user to the "users" group when installing from a live image, which allows local users to obtain sensitive information and possibly have other unspecified impacts, as demonstrated by reading /etc/shadow.Show less
1Amberdms
1Amberdms Billing System
Apr 29, 2026
Jan 10, 2014
N/A· v4
N/A· v3
1.9 LOW· v2
Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usag...Show more
Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.Show less
1Paratrooper Newrelic Project
1Paratrooper Newrelic
Apr 29, 2026
Jan 10, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The paratrooper-newrelic gem 1.0.1 for Ruby allows local users to obtain the X-Api-Key value by listing the curl process.
1Tobias Maier
1Paratrooper Pingdom
Apr 29, 2026
Jan 10, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by listing the curl process.
1Linux
1Linux Kernel
Apr 29, 2026
Jan 8, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The dgram_recvmsg function in net/ieee802154/dgram.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to o...Show more
The dgram_recvmsg function in net/ieee802154/dgram.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.Show less
1Apache
1Libcloud
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
1Openstack
1Havana
Apr 29, 2026
Jan 7, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing...Show more
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.Show less
1Dotnetblogengine
1Blogengine.net
Apr 29, 2026
Jan 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.
1Fatfreecrm
1Fat Free Crm
Apr 29, 2026
Jan 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a different vulnerability...Show more
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a different vulnerability than CVE-2013-7224.Show less