CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,065
Total CVEs
91
Critical
389
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
133
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,065)

CVE-2020-5676
7.5

CVE-2020-5676 is an information disclosure vulnerability in GROWI wiki software that allows remote attackers to access unauthorized information throug...

Dec 3, 2020
CVE-2019-1224
7.5

This CVE-2019-1224 vulnerability allows remote attackers to read sensitive memory contents from Windows RDP servers, potentially exposing credentials ...

Aug 14, 2019
CVE-2026-21524
7.4

This vulnerability in Azure Data Explorer allows unauthorized attackers to access sensitive information over the network. It affects organizations usi...

Jan 22, 2026
CVE-2025-69822
7.4

This vulnerability in Atomberg Erica Smart Fan firmware allows attackers to send crafted deauthentication frames to extract sensitive information and ...

Jan 22, 2026
CVE-2025-66623
7.4

This vulnerability in Strimzi Kafka Operator versions 0.47.0 through 0.49.0 creates an overly permissive Kubernetes Role that grants Kafka Connect and...

Dec 5, 2025
CVE-2024-54137
7.4

A correctness error in liboqs' HQC key encapsulation mechanism causes incorrect shared secret generation during decapsulation with malformed ciphertex...

Dec 6, 2024
CVE-2024-33003
7.4

This vulnerability in SAP Commerce Cloud's OCC API endpoints allows attackers to access sensitive PII data like passwords, email addresses, and coupon...

Aug 13, 2024
CVE-2022-23633
7.4

CVE-2022-23633 is a data leakage vulnerability in Ruby on Rails Action Pack where response bodies may not be properly closed, causing thread local sta...

Feb 11, 2022
CVE-2021-41124
7.4

Scrapy-splash versions before 0.8.0 expose authentication credentials to unintended targets when using HttpAuthMiddleware for Splash authentication. T...

Oct 5, 2021
CVE-2020-35681
7.4

CVE-2020-35681 is an information disclosure vulnerability in Django Channels 3.x where the legacy channels.http.AsgiHandler class incorrectly separate...

Feb 22, 2021
CVE-2025-68429
7.3

A vulnerability in Storybook versions 7.0.0 through 7.6.20, 8.0.0 through 8.6.14, 9.0.0 through 9.1.16, and 10.0.0 through 10.1.9 could expose sensiti...

Dec 17, 2025
CVE-2024-0242
7.3

CVE-2024-0242 is an information exposure vulnerability in Johnson Controls IQ Panel4 and IQ4 Hub security panel software that could allow unauthorized...

Feb 8, 2024
CVE-2025-61482
7.2

This vulnerability allows local attackers with root access on Android devices to bypass two-factor authentication in privacyIDEA Authenticator. By int...

Oct 27, 2025
CVE-2024-13911
7.2

The Database Backup and check Tables Automated With Scheduler 2024 WordPress plugin exposes sensitive database credentials to authenticated administra...

Mar 1, 2025
CVE-2025-64427
7.1

This vulnerability allows authenticated local users in ZimaOS to craft requests targeting internal IP addresses and services, potentially accessing HT...

Mar 2, 2026
CVE-2026-20641
7.1

This CVE describes a privacy vulnerability in Apple operating systems where an app could potentially identify what other apps a user has installed, ex...

Feb 11, 2026
CVE-2026-20606
7.1

This vulnerability allows applications to bypass certain privacy preferences on Apple operating systems, potentially accessing sensitive user data wit...

Feb 11, 2026
CVE-2025-55008
7.1

The AuthKit library for React Router 7+ versions 0.6.1 and below exposes sensitive authentication artifacts (sealedSession and accessToken) by returni...

Aug 9, 2025
CVE-2025-54586
7.1

GitProxy versions 1.19.1 and below allow attackers to inject hidden commits into Git packs sent to GitHub. These commits don't appear in branch histor...

Jul 30, 2025
CVE-2025-27827
7.1

An information disclosure vulnerability in Mitel MiContact Center Business's legacy chat component allows unauthenticated attackers to access sensitiv...

Jun 24, 2025
CVE-2025-31225
7.1

This CVE describes a privacy vulnerability where call history from deleted apps may still appear in Spotlight search results on iOS/iPadOS devices. Th...

May 12, 2025
CVE-2024-22269
7.1

This vulnerability allows a malicious actor with local administrative privileges on a VMware virtual machine to read privileged information from hyper...

May 14, 2024
CVE-2024-25121
7.1

This vulnerability in TYPO3 allows authenticated backend users to access files in the fallback storage via the File Abstraction Layer, potentially exp...

Feb 13, 2024
CVE-2023-28175
7.1

This vulnerability allows authenticated SSH users on Bosch VMS systems to bypass authorization controls and access internal network resources through ...

Jun 15, 2023
CVE-2022-40523
7.1

This vulnerability allows attackers to exploit indirect branch misprediction in Qualcomm chipsets to leak sensitive information from the kernel memory...

Jun 6, 2023
CVE-2022-23498
7.1

Grafana's datasource query caching feature inadvertently caches session headers, allowing authenticated users to potentially acquire other users' sess...

Feb 3, 2023
CVE-2022-1353
7.1

A local privilege escalation vulnerability in the Linux kernel's pfkey_register function allows unprivileged local users to access kernel memory. This...

Apr 29, 2022
CVE-2021-21400
7.1

This vulnerability in wire-webapp (Wire's frontend) causes the app-lock passphrase to be unintentionally sent to the most recently used chat when the ...

Apr 2, 2021
CVE-2025-53134
7.0

A race condition vulnerability in Windows Ancillary Function Driver for WinSock allows authenticated attackers to escalate privileges locally. This af...

Aug 12, 2025
CVE-2023-42820
7.0

This vulnerability in JumpServer exposes the random number seed via API, allowing attackers to predict or replay verification codes used for password ...

Sep 27, 2023
CVE-2025-60892
6.8

Raspberry Pi Imager 1.9.6 for Windows has a vulnerability where the public-key authentication setting persistently re-adds a user's id_rsa.pub key to ...

Nov 3, 2025
CVE-2025-56463
6.8

Mercusys MW305R routers running firmware version 3.30 and below expose their TLS certificate private keys, allowing attackers to decrypt encrypted tra...

Sep 26, 2025
CVE-2025-49593
6.8

Portainer Community Edition versions before STS 2.31.0 and LTS 2.27.7 contain an information disclosure vulnerability where HTTP headers (including au...

Jun 17, 2025
CVE-2025-23216
6.8

Argo CD versions before v2.13.4, v2.12.10, and v2.11.13 expose Kubernetes Secret values in error messages and diff views when invalid Secret resources...

Jan 30, 2025
CVE-2024-22260
6.8

This vulnerability in VMware Workspace One UEM allows attackers with network access to expose sensitive information. Organizations using affected vers...

Jun 27, 2024
CVE-2025-8886
6.7

This vulnerability in Usta Information Systems Inc.'s Aybs Interaktif software allows attackers to bypass authentication, access sensitive information...

Oct 10, 2025
CVE-2025-67499
6.6

The CNI portmap plugin versions 1.6.0-1.8.0 with nftables backend incorrectly forward all traffic on a host port to containers requesting HostPort for...

Dec 10, 2025
CVE-2026-30233
6.5

This CVE describes an authorization flaw in OliveTin web interface that allows authenticated users with 'view: false' permission to enumerate action b...

Mar 6, 2026
CVE-2026-24487
6.5

OpenEMR versions before 8.0.0 have an authorization bypass vulnerability in the FHIR CareTeam endpoint that allows patient-scoped tokens to access car...

Feb 25, 2026
CVE-2026-27611
6.5

This vulnerability in FileBrowser Quantum allows unauthorized access to password-protected shared files. Anyone with a share link can bypass password ...

Feb 25, 2026
CVE-2026-23983
6.5

Authenticated users in Apache Superset can exploit a disabled-by-default tagging feature to retrieve sensitive user data including password hashes and...

Feb 24, 2026
CVE-2026-23597
6.5

An information disclosure vulnerability in HPE Aruba Networking 5G Core server API error handling allows unauthenticated remote attackers to obtain se...

Feb 17, 2026
CVE-2026-20680
6.5

This CVE describes a macOS/iOS/iPadOS vulnerability where sandboxed applications can bypass security restrictions to access sensitive user data. The i...

Feb 11, 2026
CVE-2026-2317
6.5

This vulnerability in Google Chrome's animation implementation allows attackers to create malicious HTML pages that can leak data across different web...

Feb 11, 2026
CVE-2026-24098
6.5

This CVE describes an information disclosure vulnerability in Apache Airflow where authenticated users with access to specific DAGs can view import er...

Feb 9, 2026
CVE-2025-65017
6.5

This vulnerability in Decidim's private data export feature allows UUID collisions that could lead to unauthorized access to sensitive user data. Orga...

Feb 3, 2026
CVE-2025-54373
6.5

OpenEMR versions before 7.0.4 have an authorization bypass vulnerability where users without high-sensitivity privileges can view and modify clinical ...

Jan 28, 2026
CVE-2026-20800
6.5

This vulnerability in Gitea allows users who have had their access to private repositories revoked to still view issue and pull request titles through...

Jan 22, 2026
CVE-2026-20847
6.5

This vulnerability in Windows Shell allows an authorized attacker to access sensitive information and perform spoofing attacks over a network. It affe...

Jan 13, 2026
CVE-2025-14980
6.5

The BetterDocs WordPress plugin exposes sensitive information including OpenAI API keys to authenticated users with contributor-level access or higher...

Jan 9, 2026

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,065 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free