← Back
CWE-200

10,369 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,369)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
4Ros
Rox I OsRox Ii Os+1 more
Apr 29, 2026
Dec 23, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes...Show more
Siemens RuggedCom Rugged Operating System (ROS) before 3.12, ROX I OS through 1.14.5, ROX II OS through 2.3.0, and RuggedMax OS through 4.2.1.4621.22 use hardcoded private keys for SSL and SSH communication, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic by leveraging the availability of these keys within ROS files at all customer installations.Show less
1Vmware
1Vcenter Server Appliance
Apr 29, 2026
Dec 21, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors.
1Ibm
1Rational Clearquest
Apr 29, 2026
Dec 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.
1Ibm
1Lotus Notes
Apr 29, 2026
Dec 19, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via sc...Show more
IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.Show less
1Layton Technology
1Helpbox
Apr 29, 2026
Dec 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=sys_asset_id request, which is not properly handled during construction of an error page.
1Simple Gmail Login
21.1.2
1.1.3
Apr 29, 2026
Dec 11, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation pa...Show more
simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.Show less
1Vmware
1Springsource Spring Security
Apr 29, 2026
Dec 5, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and m...Show more
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.Show less
1Vmware
1Hyperic Hq
Apr 29, 2026
Dec 5, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.
1Wireshark
1Wireshark
Apr 29, 2026
Dec 5, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Wireshark 1.8.x before 1.8.4 allows remote attackers to obtain sensitive hostname information by reading pcap-ng files.
1Coleman Watts
1Webform Civicrm
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.
1Erikwebb
1Password Policy
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "client-side password history checks."
1Thinkshout
1Mandrill
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.
2Mariadb
Oracle
2Mariadb
Mysql
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user nam...Show more
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.Show less
1Opensolution
1Quick.cart
Apr 29, 2026
Nov 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.
1Remote Login Service Hackers
1Remote Login Service
Apr 29, 2026
Nov 24, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Remote Login Service (RLS) 1.0.0 does not properly clear account information when switching users, which might allow physically proximate users to obtain login credentials.
1Xen
1Xen
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The graphical console in Xen 4.0, 4.1 and 4.2 allows local OS guest administrators to obtain sensitive host resource information via the qemu monitor. NOTE: this might be a duplicate of CVE-2007-0998.
1Redhat
1Resteasy
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.
1Redhat
1Resteasy
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, a...Show more
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.Show less
1Moodle
1Moodle
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
4Canonical
MozillaOpensuse+1 more
8Firefox
Linux Enterprise DesktopLinux Enterprise Server+5 more
Apr 29, 2026
Nov 21, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass inten...Show more
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote attackers to bypass intended chrome-only restrictions on reading DOM object properties via a crafted web site.Show less