CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,063
Total CVEs
91
Critical
388
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
132
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,063)

CVE-2025-61481
10.0

MikroTik RouterOS and SwOS expose their WebFig management interface over unencrypted HTTP by default, allowing attackers on the same network path to i...

Oct 27, 2025
CVE-2025-53624
10.0

The Docusaurus gists plugin versions before 4.0.0 expose GitHub Personal Access Tokens in client-side JavaScript bundles when configured with the toke...

Jul 9, 2025
CVE-2023-49103
10.0

This vulnerability in ownCloud's graphapi app exposes PHP configuration details (phpinfo) via a third-party library URL. When accessed, it reveals web...

Nov 21, 2023
CVE-2023-42454
10.0

This vulnerability in SQLpage allows attackers to retrieve database connection strings from publicly exposed instances, potentially gaining direct acc...

Sep 18, 2023
CVE-2021-41277
10.0

This vulnerability in Metabase allows attackers to exploit the custom GeoJSON map feature to perform local file inclusion attacks. By submitting malic...

Nov 17, 2021
CVE-2025-68110
9.9

ChurchCRM versions before 6.5.3 expose sensitive database credentials in error messages, allowing attackers to obtain database host, IP, username, and...

Dec 17, 2025
CVE-2025-55190
9.9

This CVE allows API tokens with project-level permissions in Argo CD to retrieve sensitive repository credentials (usernames, passwords) through the p...

Sep 4, 2025
CVE-2024-38650
9.9

This authentication bypass vulnerability allows low-privileged attackers to access NTLM hashes of service accounts on VSPC servers. Attackers could us...

Sep 7, 2024
CVE-2023-40029
9.9

This vulnerability in Argo CD exposes sensitive cluster secret data through the API. Users with 'clusters, get' RBAC permissions can access the full s...

Sep 7, 2023
CVE-2023-28444
9.9

CVE-2023-28444 is an information exposure vulnerability in angular-server-side-configuration where environment variables intended for backend services...

Mar 24, 2023
CVE-2022-24768
9.9

CVE-2022-24768 is an improper access control vulnerability in Argo CD that allows authorized users with specific permissions to escalate privileges to...

Mar 23, 2022
CVE-2026-26273
9.8

Known social publishing platform versions 1.6.2 and earlier contain a critical authentication bypass vulnerability where password reset tokens are exp...

Feb 13, 2026
CVE-2026-0905
9.8

This vulnerability in Google Chrome allows attackers who obtain network log files to potentially extract sensitive information due to insufficient pol...

Jan 20, 2026
CVE-2026-22237
9.8

This vulnerability exposes sensitive internal API documentation in BLUVOYIX, allowing unauthenticated attackers to craft HTTP requests that abuse inte...

Jan 14, 2026
CVE-2025-47855
9.8

An unauthenticated attacker can obtain device configuration files from vulnerable FortiFone systems by sending crafted HTTP/HTTPS requests. This affec...

Jan 13, 2026
CVE-2025-11693
9.8

The Export WP Page to Static HTML & PDF WordPress plugin exposes authentication cookies in publicly accessible cookies.txt files when administrators t...

Dec 13, 2025
CVE-2025-65820
9.8

The Meatmeet Android mobile app version 1.1.2.0 contains an exported activity that can be triggered by other apps, revealing a hidden page with inform...

Dec 10, 2025
CVE-2025-54304
9.8

This vulnerability allows remote attackers to gain root privileges and execute arbitrary code on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devic...

Dec 4, 2025
CVE-2025-63958
9.8

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes an unauthenticated configuration endpoint that leaks sensitive information including database cred...

Nov 24, 2025
CVE-2017-20210
9.8

This vulnerability in QNAP Photo Station allowed unauthorized cryptocurrency mining (XMR mining) through security weaknesses. It affects QNAP NAS devi...

Nov 11, 2025
CVE-2025-11749
EPSS 85.4% 9.8

The AI Engine WordPress plugin exposes bearer tokens through an unauthenticated REST API endpoint when 'No-Auth URL' is enabled. This allows attackers...

Nov 5, 2025
CVE-2025-11710
9.8

This vulnerability allows a compromised web process to send malicious IPC messages that cause the privileged browser process to leak memory contents. ...

Oct 14, 2025
CVE-2025-9209
9.8

This vulnerability allows unauthenticated attackers to bypass authentication in the RestroPress WordPress plugin by exploiting exposed user tokens via...

Oct 3, 2025
CVE-2025-57437
9.8

Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive streaming and device configuration data through an unauthenticated Telnet service o...

Sep 22, 2025
CVE-2025-57441
9.8

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive configuration information via an unauthenticated Telnet service on port 9990. Attackers can gather ...

Sep 22, 2025
CVE-2025-22956
9.8

OPSI versions before 4.3 allow any client to access ProductPropertyState data belonging to other clients, potentially exposing sensitive information l...

Sep 8, 2025
CVE-2025-27845
9.8

ESPEC North America Web Controller 3 versions before 3.3.4 expose JWT secrets when receiving invalid authentication requests at /api/v4/auth/. This al...

Aug 14, 2025
CVE-2025-30127
9.8

This vulnerability allows attackers who gain access to Marbella KR8s Dashcam FF devices (via default/weak passwords) to download all video and audio r...

Aug 6, 2025
CVE-2025-31279
9.8

This CVE describes a permissions issue in Apple operating systems that allows applications to fingerprint users. The vulnerability affects macOS, iPad...

Jul 30, 2025
CVE-2025-43189
9.8

This vulnerability allows malicious applications to read kernel memory on macOS systems, potentially exposing sensitive system information. It affects...

Jul 30, 2025
CVE-2025-7394
9.8

This vulnerability in wolfSSL's OpenSSL compatibility layer causes predictable random number generation after fork() operations, potentially leading t...

Jul 18, 2025
CVE-2023-47029
9.8

CVE-2023-47029 is a critical vulnerability in NCR Terminal Handler v1.5.1 that allows remote attackers to execute arbitrary code and access sensitive ...

Jun 23, 2025
CVE-2025-47966
9.8

This vulnerability in Microsoft Power Automate allows unauthorized attackers to access sensitive information over a network, potentially leading to pr...

Jun 5, 2025
CVE-2025-32958
9.8

This vulnerability in Adept programming language's GitHub workflow exposes the GITHUB_TOKEN in uploaded artifacts, allowing attackers to extract it an...

Apr 21, 2025
CVE-2025-30424
9.8

A data exposure vulnerability in macOS Messages allows user contact information to leak into system logs when deleting conversations. This affects mac...

Mar 31, 2025
CVE-2025-30426
9.8

This vulnerability allows an app to enumerate a user's installed applications without proper authorization. It affects Apple devices running vulnerabl...

Mar 31, 2025
CVE-2025-24263
9.8

This CVE describes a macOS privacy vulnerability where applications could access unprotected user data stored in insecure locations. The issue affects...

Mar 31, 2025
CVE-2025-24253
9.8

A macOS vulnerability allows malicious applications to bypass symlink protections and access protected user data. This affects macOS Ventura, Sequoia,...

Mar 31, 2025
CVE-2025-24232
9.8

A state management vulnerability in macOS allows malicious applications to bypass file access restrictions and read arbitrary files on the system. Thi...

Mar 31, 2025
CVE-2025-24204
9.8

This vulnerability in macOS allows malicious applications to bypass security restrictions and access protected user data without proper authorization....

Mar 31, 2025
CVE-2025-24146
9.8

A macOS vulnerability in the Messages app where deleting conversations may expose user contact information in system logs. This affects users running ...

Jan 27, 2025
CVE-2025-24102
9.8

This CVE describes an information disclosure vulnerability in Apple operating systems where an app can determine a user's current location without pro...

Jan 27, 2025
CVE-2024-52297
9.8

Tolgee localization platform versions 3.81.1 and earlier expose all configuration properties publicly through PublicConfigurationDTO, allowing unauthe...

Nov 12, 2024
CVE-2024-8884
9.8

This CVE describes an information exposure vulnerability where credentials can be leaked when an attacker has network access to the application over H...

Oct 8, 2024
CVE-2024-6633
9.8

CVE-2024-6633 exposes default credentials for the HSQL database in FileCatalyst Workflow, allowing attackers to compromise the database if it remains ...

Aug 27, 2024
CVE-2024-42658
9.8

This vulnerability in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows remote attackers to extract sensitive information through cookie parame...

Aug 19, 2024
CVE-2024-6407
9.8

CVE-2024-6407 is a critical information disclosure vulnerability in Schneider Electric devices that allows attackers to extract credentials by sending...

Jul 11, 2024
CVE-2024-37113
9.8

CVE-2024-37113 is an unauthenticated database backup download vulnerability in the WishList Member X WordPress plugin. It allows attackers without cre...

Jul 10, 2024
CVE-2024-4300
9.8

CVE-2024-4300 is a critical information disclosure vulnerability in E-WEBInformationCo. FS-EZViewer(Web) that exposes database configuration files con...

Apr 29, 2024
CVE-2023-51154
9.8

Jizhicms v2.5 contains an arbitrary file download vulnerability in the admin plugin controller that allows attackers to download any file from the ser...

Jan 4, 2024

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,063 CVEs classified as CWE-200, with 91 rated critical and 388 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free