CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,063)
MikroTik RouterOS and SwOS expose their WebFig management interface over unencrypted HTTP by default, allowing attackers on the same network path to i...
Oct 27, 2025The Docusaurus gists plugin versions before 4.0.0 expose GitHub Personal Access Tokens in client-side JavaScript bundles when configured with the toke...
Jul 9, 2025This vulnerability in ownCloud's graphapi app exposes PHP configuration details (phpinfo) via a third-party library URL. When accessed, it reveals web...
Nov 21, 2023This vulnerability in SQLpage allows attackers to retrieve database connection strings from publicly exposed instances, potentially gaining direct acc...
Sep 18, 2023This vulnerability in Metabase allows attackers to exploit the custom GeoJSON map feature to perform local file inclusion attacks. By submitting malic...
Nov 17, 2021ChurchCRM versions before 6.5.3 expose sensitive database credentials in error messages, allowing attackers to obtain database host, IP, username, and...
Dec 17, 2025This CVE allows API tokens with project-level permissions in Argo CD to retrieve sensitive repository credentials (usernames, passwords) through the p...
Sep 4, 2025This authentication bypass vulnerability allows low-privileged attackers to access NTLM hashes of service accounts on VSPC servers. Attackers could us...
Sep 7, 2024This vulnerability in Argo CD exposes sensitive cluster secret data through the API. Users with 'clusters, get' RBAC permissions can access the full s...
Sep 7, 2023CVE-2023-28444 is an information exposure vulnerability in angular-server-side-configuration where environment variables intended for backend services...
Mar 24, 2023CVE-2022-24768 is an improper access control vulnerability in Argo CD that allows authorized users with specific permissions to escalate privileges to...
Mar 23, 2022Known social publishing platform versions 1.6.2 and earlier contain a critical authentication bypass vulnerability where password reset tokens are exp...
Feb 13, 2026This vulnerability in Google Chrome allows attackers who obtain network log files to potentially extract sensitive information due to insufficient pol...
Jan 20, 2026This vulnerability exposes sensitive internal API documentation in BLUVOYIX, allowing unauthenticated attackers to craft HTTP requests that abuse inte...
Jan 14, 2026An unauthenticated attacker can obtain device configuration files from vulnerable FortiFone systems by sending crafted HTTP/HTTPS requests. This affec...
Jan 13, 2026The Export WP Page to Static HTML & PDF WordPress plugin exposes authentication cookies in publicly accessible cookies.txt files when administrators t...
Dec 13, 2025The Meatmeet Android mobile app version 1.1.2.0 contains an exported activity that can be triggered by other apps, revealing a hidden page with inform...
Dec 10, 2025This vulnerability allows remote attackers to gain root privileges and execute arbitrary code on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devic...
Dec 4, 2025MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes an unauthenticated configuration endpoint that leaks sensitive information including database cred...
Nov 24, 2025This vulnerability in QNAP Photo Station allowed unauthorized cryptocurrency mining (XMR mining) through security weaknesses. It affects QNAP NAS devi...
Nov 11, 2025The AI Engine WordPress plugin exposes bearer tokens through an unauthenticated REST API endpoint when 'No-Auth URL' is enabled. This allows attackers...
Nov 5, 2025This vulnerability allows a compromised web process to send malicious IPC messages that cause the privileged browser process to leak memory contents. ...
Oct 14, 2025This vulnerability allows unauthenticated attackers to bypass authentication in the RestroPress WordPress plugin by exploiting exposed user tokens via...
Oct 3, 2025Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive streaming and device configuration data through an unauthenticated Telnet service o...
Sep 22, 2025The Blackmagic ATEM Mini Pro 2.7 exposes sensitive configuration information via an unauthenticated Telnet service on port 9990. Attackers can gather ...
Sep 22, 2025OPSI versions before 4.3 allow any client to access ProductPropertyState data belonging to other clients, potentially exposing sensitive information l...
Sep 8, 2025ESPEC North America Web Controller 3 versions before 3.3.4 expose JWT secrets when receiving invalid authentication requests at /api/v4/auth/. This al...
Aug 14, 2025This vulnerability allows attackers who gain access to Marbella KR8s Dashcam FF devices (via default/weak passwords) to download all video and audio r...
Aug 6, 2025This CVE describes a permissions issue in Apple operating systems that allows applications to fingerprint users. The vulnerability affects macOS, iPad...
Jul 30, 2025This vulnerability allows malicious applications to read kernel memory on macOS systems, potentially exposing sensitive system information. It affects...
Jul 30, 2025This vulnerability in wolfSSL's OpenSSL compatibility layer causes predictable random number generation after fork() operations, potentially leading t...
Jul 18, 2025CVE-2023-47029 is a critical vulnerability in NCR Terminal Handler v1.5.1 that allows remote attackers to execute arbitrary code and access sensitive ...
Jun 23, 2025This vulnerability in Microsoft Power Automate allows unauthorized attackers to access sensitive information over a network, potentially leading to pr...
Jun 5, 2025This vulnerability in Adept programming language's GitHub workflow exposes the GITHUB_TOKEN in uploaded artifacts, allowing attackers to extract it an...
Apr 21, 2025A data exposure vulnerability in macOS Messages allows user contact information to leak into system logs when deleting conversations. This affects mac...
Mar 31, 2025This vulnerability allows an app to enumerate a user's installed applications without proper authorization. It affects Apple devices running vulnerabl...
Mar 31, 2025This CVE describes a macOS privacy vulnerability where applications could access unprotected user data stored in insecure locations. The issue affects...
Mar 31, 2025A macOS vulnerability allows malicious applications to bypass symlink protections and access protected user data. This affects macOS Ventura, Sequoia,...
Mar 31, 2025A state management vulnerability in macOS allows malicious applications to bypass file access restrictions and read arbitrary files on the system. Thi...
Mar 31, 2025This vulnerability in macOS allows malicious applications to bypass security restrictions and access protected user data without proper authorization....
Mar 31, 2025A macOS vulnerability in the Messages app where deleting conversations may expose user contact information in system logs. This affects users running ...
Jan 27, 2025This CVE describes an information disclosure vulnerability in Apple operating systems where an app can determine a user's current location without pro...
Jan 27, 2025Tolgee localization platform versions 3.81.1 and earlier expose all configuration properties publicly through PublicConfigurationDTO, allowing unauthe...
Nov 12, 2024This CVE describes an information exposure vulnerability where credentials can be leaked when an attacker has network access to the application over H...
Oct 8, 2024CVE-2024-6633 exposes default credentials for the HSQL database in FileCatalyst Workflow, allowing attackers to compromise the database if it remains ...
Aug 27, 2024This vulnerability in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows remote attackers to extract sensitive information through cookie parame...
Aug 19, 2024CVE-2024-6407 is a critical information disclosure vulnerability in Schneider Electric devices that allows attackers to extract credentials by sending...
Jul 11, 2024CVE-2024-37113 is an unauthenticated database backup download vulnerability in the WishList Member X WordPress plugin. It allows attackers without cre...
Jul 10, 2024CVE-2024-4300 is a critical information disclosure vulnerability in E-WEBInformationCo. FS-EZViewer(Web) that exposes database configuration files con...
Apr 29, 2024Jizhicms v2.5 contains an arbitrary file download vulnerability in the admin plugin controller that allows attackers to download any file from the ser...
Jan 4, 2024About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,063 CVEs classified as CWE-200, with 91 rated critical and 388 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free