← Back
CWE-200

10,368 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,368)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the "Slide to Power Off" feature, which allows physically proximate attackers to see the most recently used third-party app by watchi...Show more
The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the "Slide to Power Off" feature, which allows physically proximate attackers to see the most recently used third-party app by watching the device's screen.Show less
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Messages in Apple iOS before 6, when multiple iMessage e-mail addresses are configured, does not ensure that a reply's sender address matches the recipient address of the original message, which allows remote attackers t...Show more
Messages in Apple iOS before 6, when multiple iMessage e-mail addresses are configured, does not ensure that a reply's sender address matches the recipient address of the original message, which allows remote attackers to obtain potentially sensitive information about alternate e-mail addresses in opportunistic circumstances by reading a reply.Show less
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC address of a host on a previously used network, which might allow remote attackers to obtain sensitive in...Show more
The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC address of a host on a previously used network, which might allow remote attackers to obtain sensitive information about previous device locations by sniffing an unencrypted Wi-Fi network for these packets.Show less
1Apple
1Iphone Os
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect host...Show more
CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed URL.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.
1Apple
1Safari
Apr 29, 2026
Sep 20, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book v...Show more
The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site.Show less
1Moodle
1Moodle
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by readi...Show more
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.Show less
1Moodle
1Moodle
Apr 29, 2026
Sep 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexist...Show more
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.Show less
1Siemens
2Simatic Pcs7
Wincc
Apr 29, 2026
Sep 18, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls...Show more
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.Show less
1Silverstripe
1Silverstripe
Apr 29, 2026
Sep 17, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4, when the site is running in "live mode," allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.
1Cisco
1Anyconnect Secure Mobility Client
Apr 29, 2026
Sep 16, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote at...Show more
The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.Show less
1Cybozu
1Kunai Browser For Remote Service
Apr 29, 2026
Sep 14, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that...Show more
The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.Show less
1Google
1Chrome
Apr 29, 2026
Sep 13, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.
1Ibm
6Change And Configuration Management Database
Maximo Asset ManagementMaximo Service Desk+3 more
Apr 29, 2026
Sep 10, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMD...Show more
IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote authenticated users to obtain sensitive information via unspecified vectors.Show less
1Mediawiki
1Mediawiki
Apr 29, 2026
Sep 9, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information.
1Cybozu
1Kunai
Apr 29, 2026
Sep 8, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code i...Show more
The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.Show less
1Joomla
1Joomla
Apr 29, 2026
Sep 6, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator."
1Owncloud
2Owncloud
Owncloud Server
Apr 29, 2026
Sep 5, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
(1) apps/calendar/appinfo/remote.php and (2) apps/contacts/appinfo/remote.php in ownCloud before 4.0.7 allows remote authenticated users to enumerate the registered users via unspecified vectors.
1Typo3
1Typo3
Apr 29, 2026
Sep 5, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
The configuration module in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to obtain the encryption key via unspecified vectors.
1Coppermine Gallery
1Coppermine Photo Gallery
Apr 29, 2026
Sep 4, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php,...Show more
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.Show less