← Back
CWE-200

10,367 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,367)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Debian
1Devotee
Apr 29, 2026
Aug 20, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers via a brute force attack.
1Mixi
1Mixi
Apr 29, 2026
Aug 17, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The mixi application before 4.3.0 for Android allows remote attackers to read potentially sensitive information in friends' comments via a crafted application that leverages the storage of these comments on an SD card.
2Gree
Kddi & Gree
8Gree
Gree MarketHaconiwa+5 more
Apr 29, 2026
Aug 17, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The GREE application before 1.4.0, GREE Tanken Dorirando application before 1.0.7, GREE Tsurisuta application before 1.5.0, GREE Monpura application before 1.1.1, GREE Kaizokuoukoku Columbus application before 1.3.5, GRE...Show more
The GREE application before 1.4.0, GREE Tanken Dorirando application before 1.0.7, GREE Tsurisuta application before 1.5.0, GREE Monpura application before 1.1.1, GREE Kaizokuoukoku Columbus application before 1.3.5, GREE haconiwa application before 1.1.0, GREE Seisen Cerberus application before 1.1.0, and KDDI&GREE GREE Market application before 2.1.2 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.Show less
1Ibm
1Rational Clearquest
Apr 29, 2026
Aug 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid parameter.
1Ibm
1Rational Clearquest
Apr 29, 2026
Aug 17, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3, when ClearQuest Authentication is enabled, allows remote authenticated users to read password hashes via a user query.
1Ibm
1Rational Clearquest
Apr 29, 2026
Aug 17, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp,...Show more
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sensitive information via a request to a (1) snoop, (2) hello, (3) ivt/, (4) hitcount, (5) HitCount.jsp, (6) HelloHTMLError.jsp, (7) HelloHTML.jsp, (8) HelloVXMLError.jsp, (9) HelloVXML.jsp, (10) HelloWMLError.jsp, (11) HelloWML.jsp, or (12) cqweb/j_security_check sample script.Show less
1Hp
1Fortify Software Security Center
Apr 29, 2026
Aug 16, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Hp
1Fortify Software Security Center
Apr 29, 2026
Aug 16, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HP Fortify Software Security Center 3.1, 3.3, 3.4, and 3.5 allows remote attackers to obtain sensitive information via unspecified vectors.
1Barandisolutions
1Shareyourcart
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ShareYourCart plugin 1.7.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors related to the SDK.
1George Karpouzas
1Yet Another Question & Answer System
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Yaqas (Yet Another Question & Answer System) 1.0 Alpha 1 allows remote attackers to obtain sensitive information via an invalid character in the PHPSESSID, which reveals the installation path in an error message.
1Joobi
1Com Jnews
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.
1Mysqldumper
1Mysqldumper
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.
1Mysqldumper
1Mysqldumper
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/cubemail/restore.php or (2) learn/cubemail/dump.php.
1Mybb
1Mybb
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the installation path in an error message.
1Ushahidi
1Ushahidi Platform
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attribu...Show more
The comments API in application/libraries/api/MY_Comments_Api_Object.php in the Ushahidi Platform before 2.5 allows remote attackers to obtain sensitive information about the e-mail address, IP address, and other attributes of the author of a comment via an API function call.Show less
1Rsgallery2
1Com Rsgallery2
Apr 29, 2026
Aug 10, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote attackers to list image filenames via a request for a directory URI.
1Novell
1Suse Audit Log Keeper
Apr 29, 2026
Aug 8, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
The SUSE Audit Log Keeper daemon before 0.2.1-0.4.6.1 for SUSE Manager and Spacewalk uses world-readable permissions for /etc/auditlog-keeper.conf, which allows local users to obtain passwords by reading this file.
1Pidgin
1Pidgin
Apr 29, 2026
Aug 8, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation...Show more
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.Show less
1Naver
1Nhn Japan Naver Line
Apr 29, 2026
Aug 7, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to obtain sensitive message information via a crafted application.
1Cisco
1Ios
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a...Show more
Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750.Show less