CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,065)
CVE-2020-5676 is an information disclosure vulnerability in GROWI wiki software that allows remote attackers to access unauthorized information throug...
Dec 3, 2020This CVE-2019-1224 vulnerability allows remote attackers to read sensitive memory contents from Windows RDP servers, potentially exposing credentials ...
Aug 14, 2019This vulnerability in Azure Data Explorer allows unauthorized attackers to access sensitive information over the network. It affects organizations usi...
Jan 22, 2026This vulnerability in Atomberg Erica Smart Fan firmware allows attackers to send crafted deauthentication frames to extract sensitive information and ...
Jan 22, 2026This vulnerability in Strimzi Kafka Operator versions 0.47.0 through 0.49.0 creates an overly permissive Kubernetes Role that grants Kafka Connect and...
Dec 5, 2025A correctness error in liboqs' HQC key encapsulation mechanism causes incorrect shared secret generation during decapsulation with malformed ciphertex...
Dec 6, 2024This vulnerability in SAP Commerce Cloud's OCC API endpoints allows attackers to access sensitive PII data like passwords, email addresses, and coupon...
Aug 13, 2024CVE-2022-23633 is a data leakage vulnerability in Ruby on Rails Action Pack where response bodies may not be properly closed, causing thread local sta...
Feb 11, 2022Scrapy-splash versions before 0.8.0 expose authentication credentials to unintended targets when using HttpAuthMiddleware for Splash authentication. T...
Oct 5, 2021CVE-2020-35681 is an information disclosure vulnerability in Django Channels 3.x where the legacy channels.http.AsgiHandler class incorrectly separate...
Feb 22, 2021A vulnerability in Storybook versions 7.0.0 through 7.6.20, 8.0.0 through 8.6.14, 9.0.0 through 9.1.16, and 10.0.0 through 10.1.9 could expose sensiti...
Dec 17, 2025CVE-2024-0242 is an information exposure vulnerability in Johnson Controls IQ Panel4 and IQ4 Hub security panel software that could allow unauthorized...
Feb 8, 2024This vulnerability allows local attackers with root access on Android devices to bypass two-factor authentication in privacyIDEA Authenticator. By int...
Oct 27, 2025The Database Backup and check Tables Automated With Scheduler 2024 WordPress plugin exposes sensitive database credentials to authenticated administra...
Mar 1, 2025This vulnerability allows authenticated local users in ZimaOS to craft requests targeting internal IP addresses and services, potentially accessing HT...
Mar 2, 2026This CVE describes a privacy vulnerability in Apple operating systems where an app could potentially identify what other apps a user has installed, ex...
Feb 11, 2026This vulnerability allows applications to bypass certain privacy preferences on Apple operating systems, potentially accessing sensitive user data wit...
Feb 11, 2026The AuthKit library for React Router 7+ versions 0.6.1 and below exposes sensitive authentication artifacts (sealedSession and accessToken) by returni...
Aug 9, 2025GitProxy versions 1.19.1 and below allow attackers to inject hidden commits into Git packs sent to GitHub. These commits don't appear in branch histor...
Jul 30, 2025An information disclosure vulnerability in Mitel MiContact Center Business's legacy chat component allows unauthenticated attackers to access sensitiv...
Jun 24, 2025This CVE describes a privacy vulnerability where call history from deleted apps may still appear in Spotlight search results on iOS/iPadOS devices. Th...
May 12, 2025This vulnerability allows a malicious actor with local administrative privileges on a VMware virtual machine to read privileged information from hyper...
May 14, 2024This vulnerability in TYPO3 allows authenticated backend users to access files in the fallback storage via the File Abstraction Layer, potentially exp...
Feb 13, 2024This vulnerability allows authenticated SSH users on Bosch VMS systems to bypass authorization controls and access internal network resources through ...
Jun 15, 2023This vulnerability allows attackers to exploit indirect branch misprediction in Qualcomm chipsets to leak sensitive information from the kernel memory...
Jun 6, 2023Grafana's datasource query caching feature inadvertently caches session headers, allowing authenticated users to potentially acquire other users' sess...
Feb 3, 2023A local privilege escalation vulnerability in the Linux kernel's pfkey_register function allows unprivileged local users to access kernel memory. This...
Apr 29, 2022This vulnerability in wire-webapp (Wire's frontend) causes the app-lock passphrase to be unintentionally sent to the most recently used chat when the ...
Apr 2, 2021A race condition vulnerability in Windows Ancillary Function Driver for WinSock allows authenticated attackers to escalate privileges locally. This af...
Aug 12, 2025This vulnerability in JumpServer exposes the random number seed via API, allowing attackers to predict or replay verification codes used for password ...
Sep 27, 2023Raspberry Pi Imager 1.9.6 for Windows has a vulnerability where the public-key authentication setting persistently re-adds a user's id_rsa.pub key to ...
Nov 3, 2025Mercusys MW305R routers running firmware version 3.30 and below expose their TLS certificate private keys, allowing attackers to decrypt encrypted tra...
Sep 26, 2025Portainer Community Edition versions before STS 2.31.0 and LTS 2.27.7 contain an information disclosure vulnerability where HTTP headers (including au...
Jun 17, 2025Argo CD versions before v2.13.4, v2.12.10, and v2.11.13 expose Kubernetes Secret values in error messages and diff views when invalid Secret resources...
Jan 30, 2025This vulnerability in VMware Workspace One UEM allows attackers with network access to expose sensitive information. Organizations using affected vers...
Jun 27, 2024This vulnerability in Usta Information Systems Inc.'s Aybs Interaktif software allows attackers to bypass authentication, access sensitive information...
Oct 10, 2025The CNI portmap plugin versions 1.6.0-1.8.0 with nftables backend incorrectly forward all traffic on a host port to containers requesting HostPort for...
Dec 10, 2025This CVE describes an authorization flaw in OliveTin web interface that allows authenticated users with 'view: false' permission to enumerate action b...
Mar 6, 2026OpenEMR versions before 8.0.0 have an authorization bypass vulnerability in the FHIR CareTeam endpoint that allows patient-scoped tokens to access car...
Feb 25, 2026This vulnerability in FileBrowser Quantum allows unauthorized access to password-protected shared files. Anyone with a share link can bypass password ...
Feb 25, 2026Authenticated users in Apache Superset can exploit a disabled-by-default tagging feature to retrieve sensitive user data including password hashes and...
Feb 24, 2026An information disclosure vulnerability in HPE Aruba Networking 5G Core server API error handling allows unauthenticated remote attackers to obtain se...
Feb 17, 2026This CVE describes a macOS/iOS/iPadOS vulnerability where sandboxed applications can bypass security restrictions to access sensitive user data. The i...
Feb 11, 2026This vulnerability in Google Chrome's animation implementation allows attackers to create malicious HTML pages that can leak data across different web...
Feb 11, 2026This CVE describes an information disclosure vulnerability in Apache Airflow where authenticated users with access to specific DAGs can view import er...
Feb 9, 2026This vulnerability in Decidim's private data export feature allows UUID collisions that could lead to unauthorized access to sensitive user data. Orga...
Feb 3, 2026OpenEMR versions before 7.0.4 have an authorization bypass vulnerability where users without high-sensitivity privileges can view and modify clinical ...
Jan 28, 2026This vulnerability in Gitea allows users who have had their access to private repositories revoked to still view issue and pull request titles through...
Jan 22, 2026This vulnerability in Windows Shell allows an authorized attacker to access sensitive information and perform spoofing attacks over a network. It affe...
Jan 13, 2026The BetterDocs WordPress plugin exposes sensitive information including OpenAI API keys to authenticated users with contributor-level access or higher...
Jan 9, 2026About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,065 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free