← Back
CWE-200

10,357 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,357)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Dec 16, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers...Show more
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by smb/user/list and certain other files.Show less
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Dec 16, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page,...Show more
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a database connection string within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by client@2/domain@1/hosting/aspdotnet/.Show less
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Dec 16, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain o...Show more
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.Show less
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Dec 16, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive infor...Show more
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by get_password.php and certain other files.Show less
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Dec 16, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as de...Show more
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in client@2/domain@1/odbc/dsn@1/properties/.Show less
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Dec 16, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading t...Show more
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 includes an RFC 1918 IP address within a web page, which allows remote attackers to obtain potentially sensitive information by reading this page, as demonstrated by admin/home/admin and certain other files.Show less
1Parallels
1Parallels Plesk Panel
Apr 29, 2026
Dec 16, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by inter...Show more
The Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demonstrated by cookies used by login_up.php3 and certain other files.Show less
1Digium
1Asterisk
Apr 29, 2026
Dec 15, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The handle_request_info function in channels/chan_sip.c in Asterisk Open Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is enabled, allows remote attackers to cause a denial of service (NULL pointe...Show more
The handle_request_info function in channels/chan_sip.c in Asterisk Open Source 1.6.2.x before 1.6.2.21 and 1.8.x before 1.8.7.2, when automon is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted sequence of SIP requests.Show less
1Digium
1Asterisk
Apr 29, 2026
Dec 15, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP userna...Show more
The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP username exists, which allows remote attackers to enumerate usernames via a series of requests.Show less
1Microsoft
1Internet Explorer
Apr 29, 2026
Dec 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain...Show more
Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Content-Disposition Information Disclosure Vulnerability."Show less
1Blackberry
1Blackberry Tablet Os
Apr 29, 2026
Dec 8, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain privileges via a crafted configuration file in a backup archive.
1Novell
2Groupwise Messenger
Messenger
Apr 29, 2026
Dec 8, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The server process in Novell Messenger 2.1 and 2.2.x before 2.2.1, and Novell GroupWise Messenger 2.04 and earlier, allows remote attackers to read from arbitrary memory locations via a crafted command.
1Google
1Chrome
Apr 29, 2026
Dec 7, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted H...Show more
The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overlap CVE-2010-2264.Show less
1Opera
1Opera Browser
Apr 29, 2026
Dec 7, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Cascading Style Sheets (CSS) implementation in Opera 10.5 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML d...Show more
The Cascading Style Sheets (CSS) implementation in Opera 10.5 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.Show less
1Mozilla
3Firefox
SeamonkeyThunderbird
Apr 29, 2026
Dec 7, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain...Show more
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.Show less
1Microsoft
2Ie
Internet Explorer
Apr 29, 2026
Dec 7, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visit...Show more
The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.Show less
1Asus
2Rt N56u
Rt N56u Firmware
Apr 29, 2026
Nov 21, 2011
N/A· v4
N/A· v3
3.3 LOW· v2
QIS_wizard.htm on the ASUS RT-N56U router with firmware before 1.0.1.4o allows remote attackers to obtain the administrator password via a flag=detect request.
1Owasp Java Html Sanitizer Project
1Owasp Java Html Sanitizer
Apr 29, 2026
Nov 17, 2011
N/A· v4
N/A· v3
2.6 LOW· v2
OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT...Show more
OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element.Show less
1Mahara
1Mahara
Apr 29, 2026
Nov 15, 2011
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.
1Apple
1Iphone Os
Apr 29, 2026
Nov 11, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.