← Back
CWE-200

10,330 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,330)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intervations
1Navicopa Web Server
Apr 23, 2026
Oct 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
1Freewebscriptz
1Hubscript
Apr 23, 2026
Oct 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, which calls the phpinfo function.
1Xerver
1Xerver
Apr 23, 2026
Oct 5, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
1Cisco
2Ace Web Application Firewall
Ace Xml Gateway
Apr 23, 2026
Sep 29, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or...Show more
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.Show less
1Radactive
1I Load
Apr 23, 2026
Sep 29, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.
1Uebimiau
1Uebimiau
Apr 23, 2026
Sep 15, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request fo...Show more
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.Show less
2Apple
Canonical
2Iphone Os
Ubuntu Linux
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain...Show more
The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.Show less
1Apple
1Iphone Os
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
2.1 LOW· v2
The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.
1Oxid
1Eshop
Apr 23, 2026
Sep 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.
1Coppermine Gallery
1Coppermine Photo Gallery
Apr 23, 2026
Sep 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.
1Hp
1Performance Insight
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as demonstrated by certain modules in VulnDisco Pack Professional 8.11....Show more
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 on Windows allow attackers to obtain sensitive information via unknown vectors, as demonstrated by certain modules in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.Show less
1Rubyonrails
1Rails
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to...Show more
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.Show less
1Docebo
1Docebo
Apr 23, 2026
Sep 2, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3) lib/lib.domxml5.php, or (4) menu/menu_...Show more
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3) lib/lib.domxml5.php, or (4) menu/menu_over.php in doceboCore/; or (5) class/class.conf_cms.php, (6) lib/lib.compose.php, (7) modules/chat/teleskill.php, or (8) class/class.admin_menu_cms.php in doceboCms/; which reveals the installation path in an error message.Show less
1Intralearn
1Intralearn
Apr 23, 2026
Sep 1, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IntraLearn Software IntraLearn 2.1, and possibly other versions before 4.2.3, allows remote attackers to obtain sensitive information via a direct request to (1) Knowledge_Impact_Course.htm, (2) LRN-formatted_Course.htm,...Show more
IntraLearn Software IntraLearn 2.1, and possibly other versions before 4.2.3, allows remote attackers to obtain sensitive information via a direct request to (1) Knowledge_Impact_Course.htm, (2) LRN-formatted_Course.htm, or (3) Create_Course.htm in help/1/Instructor/, which reveals the installation path in an error message.Show less
1Phpbb
1Phpbb
Apr 23, 2026
Sep 1, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remot...Show more
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Apr 23, 2026
Aug 28, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_A...Show more
The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Apr 23, 2026
Aug 28, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by ca...Show more
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.Show less
1Paul Arbogast
1Accms
Apr 23, 2026
Aug 25, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials,...Show more
All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials, via a direct request to accms.dat.Show less
1Ocean12tech
1Faq Manager Pro
Apr 23, 2026
Aug 25, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for admin/o12faq.mdb.
1Ibm
1Websphere Commerce Suite
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and d...Show more
The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and database and filesystem details, via direct requests for configuration files.Show less