CWE-200
10,370 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,370)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Active Directory Federation Services Apr 29, 2026 Aug 14, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Active Directory Federation Services (AD FS) 1.x through 2.1 on Windows Server 2003 R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allows remote attackers to obtain sensitive information ab...Show more |
The NDMP protocol implementation in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote authenticated users to obtain sensitive host-version information via unspecified vectors. |
1Cisco 1Unified Communications Manager Apr 29, 2026 Aug 5, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The web portal in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive stack-trace information via unspecified vectors that trigger a stack exception, aka Bug ID CSCug34...Show more |
The HTTPAuthorized function in bitcoinrpc.cpp in bitcoind 0.8.1 provides information about authentication failure upon detecting the first incorrect byte of a password, which makes it easier for remote attackers to deter...Show more |
EMC NetWorker 7.6.x and 8.x before 8.1 allows local users to obtain sensitive configuration information by leveraging operating-system privileges to perform decryption with nsradmin. |
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files. |
phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class....Show more |
phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php...Show more |
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML sour...Show more |
1Siemens 2Enterprise Openscape Branch Openscape Session Border ControllerApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to read arbitrary files via unspecified...Show more |
1Siemens 2Enterprise Openscape Branch Openscape Session Border ControllerApr 29, 2026 Jul 18, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to obtain sensitive server and statistic...Show more |
1Oracle 1Supply Chain Products Suite Apr 29, 2026 Jul 17, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the Oracle Agile Product Collaboration component in Oracle Supply Chain Products Suite 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders...Show more |
1Oracle 1Supply Chain Products Suite Apr 29, 2026 Jul 17, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Security. |
1Cisco 1Secure Access Control System Apr 29, 2026 Jul 15, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that tr...Show more |
Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for sign-in and subsequent sync operations, which makes it easier for remote...Show more |
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Ent...Show more |
1Symantec 2Security Information Manager Security Information Manager ApplianceApr 29, 2026 Jul 8, 2013 N/A· v4 N/A· v3 2.9 LOW· v2 The management console (aka Java console) on the Symantec Security Information Manager (SSIM) appliance 4.7.x and 4.8.x before 4.8.1 allows remote attackers to obtain sensitive information via unspecified web-GUI API cal...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelApr 29, 2026 Jul 4, 2013 N/A· v4 N/A· v3 2.1 LOW· v2 The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive...Show more |
1Ibm 2Sterling B2b Integrator Sterling File GatewayApr 29, 2026 Jul 3, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnera...Show more |
1Ibm 2Sterling B2b Integrator Sterling File GatewayApr 29, 2026 Jul 3, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors, a different vulnera...Show more |