← Back
CWE-200

10,370 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,370)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Rational Directory Server
Apr 29, 2026
May 28, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted para...Show more
IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.Show less
1Google
1Chrome
Apr 29, 2026
May 22, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
1Openstack
1Keystone
Apr 29, 2026
May 21, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
1Adobe
2Acrobat
Acrobat Reader
Apr 29, 2026
May 16, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to obtain sensitive information via unspecified vectors.
1Microsoft
1Visio
Apr 29, 2026
May 15, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Ent...Show more
Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
May 15, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information...Show more
Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information Disclosure Vulnerability."Show less
1Ibm
1Sterling Secure Proxy
Apr 29, 2026
May 10, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-server version data in (1) an unspecified page title and (2) an unspeci...Show more
IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-server version data in (1) an unspecified page title and (2) an unspecified HTTP header field, which allows remote attackers to obtain potentially sensitive information by reading a version string.Show less
1Softbanktech
1Online Service Gate
Apr 29, 2026
May 9, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via unspecified vectors.
1Gwos
1Groundwork Monitor
Apr 29, 2026
May 8, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to obtain sensitive information via a direct request for (1) a configuration file, (2) a database dump, or (3) the Tomcat status...Show more
The NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to obtain sensitive information via a direct request for (1) a configuration file, (2) a database dump, or (3) the Tomcat status context.Show less
1Cisco
2Webex Meetings Server
Webex Node For Mcs
Apr 29, 2026
May 3, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka Bug IDs CSCue36664 and CSCue36629.
1Emc
1Avamar
Apr 29, 2026
May 3, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.
2Canonical
Djangoproject
2Django
Ubuntu Linux
Apr 29, 2026
May 2, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obta...Show more
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.Show less
1Zend
1Zend Framework
Apr 29, 2026
May 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, a...Show more
The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack.Show less
1Hp
1Service Manager Web Tier
Apr 29, 2026
May 2, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspecified vectors.
2Canonical
Haxx
3Curl
LibcurlUbuntu Linux
Apr 29, 2026
Apr 29, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a U...Show more
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Apr 29, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from ker...Show more
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.Show less
1Cisco
1Ios Xr
Apr 29, 2026
Apr 29, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Memory leak in the SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (memory consumption and process restart) via crafted SNMP packets, aka Bug ID CSCue31546.
1Cisco
6Unified Computing System 6120xp Fabric Interconnect
Unified Computing System 6140xp Fabric InterconnectUnified Computing System 6248up Fabric Interconnect+3 more
Apr 29, 2026
Apr 25, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensitive information by reading a (1) technical-support bundle file or (2)...Show more
The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensitive information by reading a (1) technical-support bundle file or (2) on-device configuration backup, aka Bug ID CSCtq86543.Show less
1Google
1Authenticator
Apr 29, 2026
Apr 24, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a share...Show more
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.Show less
1Ibm
1Infosphere Replication Server
Apr 29, 2026
Apr 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a list of all user accounts, along with information about whether each acc...Show more
The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a list of all user accounts, along with information about whether each account requires a password, via unspecified vectors.Show less