← Back
CWE-200

10,359 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,359)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opera
1Opera Browser
Apr 29, 2026
Mar 28, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access...Show more
Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.Show less
1Atmail
1Atmail Open
Apr 29, 2026
Mar 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
@Mail WebMail Client in AtMail Open-Source 1.04 and earlier allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
1Ibm
1Tivoli Endpoint Manager
Apr 29, 2026
Mar 22, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for...Show more
The (1) webreports, (2) post/create-role, and (3) post/update-role programs in IBM Tivoli Endpoint Manager (TEM) before 8.2 do not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Janetter
1Janetter
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.
1Netmechanica
1Netdecision
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as...Show more
The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code of NtDecision script files with a .nd extension via an invalid version number in an HTTP request, as demonstrated using default.nd. NOTE: some of these details are obtained from third party information.Show less
1Netmechanica
1Netdecision
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboard to attempt to access a non-existent r...Show more
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a request with a trailing "?" character, which causes Dashboard to attempt to access a non-existent resource. NOTE: some of these details are obtained from third party information.Show less
1Kylegilman
1Video Embed & Thumbnail Generator
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Media Upload form in the Video Embed & Thumbnail Generator plugin before 2.0 for WordPress allows remote attackers to obtain the installation path via unknown vectors.
1Iwork
1Webglimpse
Apr 29, 2026
Mar 19, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.
1Vmware
1Vcenter Orchestrator
Apr 29, 2026
Mar 16, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated...Show more
The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.Show less
1Mozilla
4Firefox
SeamonkeyThunderbird+1 more
Apr 29, 2026
Mar 14, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey befo...Show more
The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to obtain sensitive information from process memory via vectors that trigger an out-of-bounds read.Show less
1Tibco
4Spotfire Analytics Server
Spotfire ProfessionalSpotfire Server+1 more
Apr 29, 2026
Mar 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Servic...Show more
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a crafted URL.Show less
1Tibco
5Activematrix Bpm
Activematrix Businessworks Service EngineActivematrix Service Bus+2 more
Apr 29, 2026
Mar 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM befor...Show more
The server in TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0 allows remote attackers to discover credentials via unspecified vectors.Show less
1Tibco
7Activematrix Bpm
Activematrix BusinessworksActivematrix Businessworks Service Engine+4 more
Apr 29, 2026
Mar 13, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distributio...Show more
TIBCO ActiveMatrix Runtime Platform in Service Grid and Service Bus 2.x before 2.3.2 and BusinessWorks Service Engine before 5.8.2; TIBCO ActiveMatrix Platform in TIBCO Silver Fabric ActiveMatrix Service Grid Distribution 3.1.3, Service Grid and Service Bus 3.x before 3.1.5, BusinessWorks Service Engine 5.9.x before 5.9.3, and BPM before 1.3.0; TIBCO BusinessEvents Runtime in Enterprise and Inference Editions 3.x before 3.0.3, Standard Edition 4.x before 4.0.2, and Standard Edition and Express 5.0.0; and TIBCO BusinessWorks Engine in TIBCO Silver Fabric ActiveMatrix BusinessWorks Distribution 5.9.2 and ActiveMatrix BusinessWorks before 5.9.3 allow remote attackers to obtain sensitive information via a crafted URL.Show less
1Ibm
6Maximo Asset Management
Maximo Asset Management EssentialsMaximo Service Desk+3 more
Apr 29, 2026
Mar 13, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IB...Show more
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.Show less
1Apple
1Safari
Apr 29, 2026
Mar 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.
1Apple
1Safari
Apr 29, 2026
Mar 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remote web servers to track users via a cookie.
1Cookpad
2Android Activities
Android Mykitchen
Apr 29, 2026
Mar 2, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted applic...Show more
The Cookpad 1.5.16 and earlier and Cookpad Noseru 1.1.1 and earlier applications for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.Show less
1Advantech
1Advantech Webaccess
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
1Rabidhamster
1R2/extreme
Apr 29, 2026
Feb 21, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
RabidHamster R2/Extreme 1.65 and earlier uses a small search space of values for the PIN number, which allows remote attackers to obtain the PIN number via a brute force attack.
1Microsoft
1Internet Explorer
Apr 29, 2026
Feb 14, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka...Show more
Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Copy and Paste Information Disclosure Vulnerability."Show less