CWE-540
30 CVEs • Abstraction: Base
Inclusion of Sensitive Information in Source Code
Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.
CVEs (30)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Keerti1924 1Php Mysql User Signup Login System Jun 17, 2026 Mar 7, 2024 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive informat...Show more |
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769. |
1Sangfor 1Next Gen Application Firewall Jun 17, 2026 Oct 10, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an in...Show more |
1Dell 3Replay Manager For Vmware Storage Integration Tools For VmwareStorage Vsphere Client PluginJun 17, 2026 Aug 16, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Dell Storage Integration Tools for VMware (DSITV) and Dell Storage vSphere Client Plugin (DSVCP) versions prior to 6.1.1 and Replay Manager for VMware (RMSV) versions prior to 3.1.2 contain an information disclosure v...Show more |
1Sick 7Ftmg Esd15axx Firmware Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 moreJun 17, 2026 May 15, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usern...Show more |
1Cisco 16Business 220 16p 2g Firmware Business 220 16t 2g FirmwareBusiness 220 24fp 4g Firmware+13 moreJun 17, 2026 Oct 6, 2021 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account....Show more |
1Cisco 16Business 220 16p 2g Firmware Business 220 16t 2g FirmwareBusiness 220 24fp 4g Firmware+13 moreJun 17, 2026 Oct 6, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account....Show more |
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS att...Show more |
Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read application data. This issue affects: QNAP Sy...Show more |
1Cisco 4Content Security Management Appliance Email Security ApplianceIronport Web Security Appliance+1 moreJun 17, 2026 May 6, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA), Cisco Email Security Appliance (ESA), and Cisco Web Security Appliance (WSA) could al...Show more |