CWE-200— Exposure of Sensitive Information to an Unauthorized Actor
8,637 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-200page 61 of 173
- CVE-2018-18644MEDIUMCVSS 6.5EG 6.52018-12-04
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integration.
- CVE-2018-18645MEDIUMCVSS 4.3EG 4.32018-12-04
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for Information Exposure via unsubscribe links in email replies.
- CVE-2018-18648HIGHCVSS 7.5EG 7.52018-12-04
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through an Error Message.
- CVE-2018-18655MEDIUMCVSS 4.3EG 4.32018-10-26
Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.
- CVE-2018-18657HIGHCVSS 7.5EG 7.52018-10-26
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Information Disclosure via /gateway/services/EdgeServiceImpl issue.
- CVE-2018-18658HIGHCVSS 7.5EG 7.52018-10-26
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates/Config/FullUpdateSettings.xml issue.
- CVE-2018-18710MEDIUMCVSS 5.5EG 5.52018-10-29
An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes wi…
- CVE-2018-1874MEDIUMCVSS 4.6EG 4.62019-04-02
IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access to the system. IBM X-Force ID: 151636.
- CVE-2018-18762MEDIUMCVSS 6.5EG 6.52019-03-21
SaltOS 3.1 r8126 contains a database download vulnerability.
- CVE-2018-18778MEDIUMCVSS 6.5EG 9.02018-10-29
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
- CVE-2018-1878MEDIUMCVSS 5.3EG 5.32018-11-02
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.
- CVE-2018-18839MEDIUMCVSS 5.3EG 5.32019-06-18
An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional.
- CVE-2018-1885MEDIUMCVSS 5.3EG 5.32019-04-08
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow an unauthenticated attacker to obtain sensitve information using a specially cracted HTTP request. IBM X-Force ID: 152020.
- CVE-2018-1886MEDIUMCVSS 5.3EG 5.32018-12-13
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 152021.
- CVE-2018-18865HIGHCVSS 8.1EG 8.12018-11-20
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure.
- CVE-2018-18941CRITICALCVSS 9.8EG 9.82019-01-31
In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=admin HTML source code, and then creating …
- CVE-2018-18975HIGHCVSS 7.5EG 7.52019-05-06
An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the app and Ascensia backend servers because of a weak certificate-pinning implementation, leading to disc…
- CVE-2018-18977HIGHCVSS 7.5EG 7.52019-05-06
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the codebase to extract sensitive data that contributes to the disclosure of medical information of patien…
- CVE-2018-1902LOWCVSS 3.1EG 4.32019-03-11
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information which could be used to launch further attacks against the system. IBM X-Force ID: 152531.
- CVE-2018-19039MEDIUMCVSS 6.5EG 6.52018-12-13
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
- CVE-2018-19045HIGHCVSS 7.5EG 7.52018-11-08
keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.
- CVE-2018-19046MEDIUMCVSS 4.7EG 4.72018-11-08
keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /t…
- CVE-2018-19075MEDIUMCVSS 5.3EG 5.32018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall feature makes it easier f…
- CVE-2018-19120HIGHCVSS 7.5EG 7.52018-11-29
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
- CVE-2018-19133MEDIUMCVSS 5.3EG 5.32018-11-09
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address.
- CVE-2018-19148LOWCVSS 3.7EG 3.72018-11-10
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 …
- CVE-2018-1917LOWCVSS 3.5EG 6.52019-04-02
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclose sensitive information. IBM X-Force ID: 152784.
- CVE-2018-19194MEDIUMCVSS 5.3EG 5.32018-11-12
An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to open stream" error message.
- CVE-2018-19205HIGHCVSS 7.5EG 7.52018-11-12
Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnu…
- CVE-2018-19226MEDIUMCVSS 5.3EG 5.32018-11-12
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /data/0/admin.txt URI.
- CVE-2018-19246HIGHCVSS 7.5EG 7.52018-11-13
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. This occurs because the aeb067ca0aa9a3193dce3a7264c90187 app_key val…
- CVE-2018-1929MEDIUMCVSS 4.3EG 4.32019-03-14
IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.
- CVE-2018-1932MEDIUMCVSS 4.9EG 4.92019-01-08
IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.
- CVE-2018-1935MEDIUMCVSS 4.3EG 4.32018-12-06
IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315.
- CVE-2018-19413MEDIUMCVSS 4.3EG 4.32018-12-14
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly con…
- CVE-2018-19440MEDIUMCVSS 5.3EG 5.32019-01-30
ARM Trusted Firmware-A allows information disclosure.
- CVE-2018-19456HIGHCVSS 7.5EG 7.52019-05-07
The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders and files, as demonstrated by download.sql.
- CVE-2018-19487HIGHCVSS 7.5EG 7.52019-03-21
The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information a…
- CVE-2018-1949MEDIUMCVSS 4.3EG 4.32019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153429.
- CVE-2018-1950MEDIUMCVSS 4.3EG 4.32019-02-21
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that includes sensitive information about its environment, users, or associated data which could be used in further attacks …
- CVE-2018-1957MEDIUMCVSS 4.0EG 5.52018-12-10
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is acce…
- CVE-2018-19609MEDIUMCVSS 6.5EG 6.52018-11-27
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
- CVE-2018-1961MEDIUMCVSS 5.3EG 5.32019-04-29
IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages. IBM X-Force ID: 153657.
- CVE-2018-19643MEDIUMCVSS 4.7EG 7.52019-03-27
Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
- CVE-2018-1968MEDIUMCVSS 5.3EG 5.32019-07-11
IBM Security Identity Manager 7.0.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 153749.
- CVE-2018-19718MEDIUMCVSS 5.3EG 5.32019-01-18
Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead to exposure of the privileges granted to a session.
- CVE-2018-1976MEDIUMCVSS 4.9EG 4.92019-01-29
IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.
- CVE-2018-19854MEDIUMCVSS 4.7EG 4.72018-12-04
An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially l…
- CVE-2018-1990MEDIUMCVSS 5.3EG 5.32019-05-10
IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially crafted HTTP request. IBM X-Force ID: 154283.
- CVE-2018-1991LOWCVSS 2.7EG 2.72019-05-22
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.
Map vulnerabilities like CWE-200 to your infrastructure
EchelonGraph correlates every CVE — across CWE-200 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →