CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,066
Total CVEs
92
Critical
389
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
133
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,066)

CVE-2025-14980
6.5

The BetterDocs WordPress plugin exposes sensitive information including OpenAI API keys to authenticated users with contributor-level access or higher...

Jan 9, 2026
CVE-2025-68436
6.5

This vulnerability allows authenticated users on Craft CMS installations to expose sensitive assets through maliciously crafted requests targeting use...

Jan 5, 2026
CVE-2025-67732
6.5

Dify versions before 1.11.0 expose API keys in plaintext to frontend users, allowing non-administrators to view and potentially misuse them. This vuln...

Jan 5, 2026
CVE-2025-15033
6.5

A vulnerability in WooCommerce allows logged-in customers to access guest customer order data on sites with specific configurations. This affects WooC...

Dec 22, 2025
CVE-2025-8305
6.5

An authenticated local user can access sensitive information from debug files in Identity Agent for Terminal Services, potentially allowing them to cl...

Dec 22, 2025
CVE-2025-8304
6.5

An authenticated local user on a Windows Terminal Server can access sensitive information in Windows Registry keys for Check Point Identity Agent, all...

Dec 22, 2025
CVE-2025-52493
6.5

PagerDuty Runbook exposes stored secrets in the webpage DOM on configuration pages, allowing administrative users to view masked passwords by changing...

Dec 10, 2025
CVE-2025-64670
6.5

This vulnerability in Microsoft Graphics Component allows an authenticated attacker to access sensitive information over a network connection. It affe...

Dec 9, 2025
CVE-2025-66027
6.5

This CVE describes an information disclosure vulnerability in Rallly, an open-source scheduling tool. It allows unauthorized access to participant nam...

Nov 29, 2025
CVE-2025-13683
6.5

This vulnerability in Devolutions Server and Remote Desktop Manager exposes credentials through unintended requests, potentially allowing attackers to...

Nov 28, 2025
CVE-2025-63212
6.5

GatesAir Flexiva-LX devices expose session IDs in publicly accessible log files, allowing unauthenticated attackers to hijack admin sessions. This aff...

Nov 19, 2025
CVE-2025-62206
6.5

This vulnerability in Microsoft Dynamics 365 (on-premises) allows unauthorized attackers to access sensitive information over the network. Attackers c...

Nov 11, 2025
CVE-2025-62721
6.5

This vulnerability in LinkAce allows any authenticated user to access all links, lists, and tags from all users in the system, regardless of ownership...

Nov 4, 2025
CVE-2025-62720
6.5

This vulnerability in LinkAce allows any authenticated user to export the entire database of links, including private links belonging to other users. ...

Nov 4, 2025
CVE-2025-6239
6.5

ManageEngine Applications Manager versions 176800 and below contain an information disclosure vulnerability in the File/Directory monitor component. T...

Oct 21, 2025
CVE-2025-61907
6.5

This vulnerability allows authenticated API users in Icinga 2 to bypass permission restrictions and access sensitive information they shouldn't have a...

Oct 16, 2025
CVE-2025-59921
6.5

An authenticated attacker can access sensitive information on vulnerable FortiADC devices by sending specially crafted HTTP/HTTPS requests. This affec...

Oct 14, 2025
CVE-2025-43356
6.5

This vulnerability allows malicious websites to access device sensor data (like motion, orientation, or environmental sensors) without obtaining user ...

Sep 15, 2025
CVE-2025-56467
6.5

This vulnerability in AXIS BANK LIMITED Axis Mobile App 9.9 allows attackers to access sensitive banking information without requiring UPI PIN authent...

Sep 12, 2025
CVE-2025-53728
6.5

This vulnerability in Microsoft Dynamics 365 (on-premises) allows unauthorized attackers to access sensitive information over the network. Attackers c...

Aug 12, 2025
CVE-2025-50154
EPSS 11.9% 6.5

This vulnerability in Windows File Explorer allows unauthorized attackers to perform network spoofing by exploiting exposed sensitive information. It ...

Aug 12, 2025
CVE-2025-54380
6.5

Opencast versions before 17.6 incorrectly send hashed global system account credentials to attacker-controlled URLs when fetching mediapackage element...

Jul 26, 2025
CVE-2025-7919
6.5

WinMatrix3 Web package has an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands. This enables...

Jul 21, 2025
CVE-2025-53512
6.5

This vulnerability allows unauthorized users to access the /log endpoint on Juju controllers, exposing debug messages that may contain sensitive infor...

Jul 8, 2025
CVE-2025-39204
6.5

This vulnerability in MicroSCADA X SYS600's web interface allows attackers to craft malicious filtering queries that bypass authorization controls, po...

Jun 24, 2025
CVE-2025-5690
6.5

PostgreSQL Anonymizer versions 2.0-2.1 contain a data exposure vulnerability where users with masked access can bypass masking rules and read original...

Jun 4, 2025
CVE-2025-27980
6.5

Cashbook v4.0.3 contains an arbitrary file read vulnerability in the /api/entry/flow/invoice/show endpoint. Attackers can exploit this to read sensiti...

Apr 15, 2025
CVE-2025-26667
6.5

This vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized network attackers to access sensitive information. It affec...

Apr 8, 2025
CVE-2025-3031
6.5

This vulnerability allows an attacker to read 32 bits of sensitive data from the stack in JIT-compiled JavaScript functions. It affects Firefox web br...

Apr 1, 2025
CVE-2025-24239
6.5

This CVE describes a macOS code-signing downgrade vulnerability that allows malicious applications to bypass security restrictions and access protecte...

Mar 31, 2025
CVE-2025-29497
6.5

CVE-2025-29497 is a memory leak vulnerability in libming v0.4.8's parseSWF_MORPHFILLSTYLES function that allows attackers to cause denial of service t...

Mar 27, 2025
CVE-2025-29488
6.5

CVE-2025-29488 is a memory leak vulnerability in libming v0.4.8's parseSWF_INITACTION function. This vulnerability allows attackers to cause denial of...

Mar 27, 2025
CVE-2025-1635
6.5

This vulnerability in Devolutions Remote Desktop Manager allows authenticated users to export hub data sources containing their authenticated session ...

Mar 13, 2025
CVE-2025-24071
EPSS 57.7% 6.5

This vulnerability in Windows File Explorer allows unauthorized attackers to access sensitive information and perform spoofing attacks over a network....

Mar 11, 2025
CVE-2025-25192
6.5

CVE-2025-25192 allows low-privileged users in GLPI to enable debug mode, potentially exposing sensitive system information. This affects GLPI installa...

Feb 25, 2025
CVE-2025-26310
6.5

Multiple memory leaks in ABC file parsing functions in libming v0.4.8 allow attackers to cause denial of service through crafted ABC files. This affec...

Feb 20, 2025
CVE-2025-25942
6.5

A memory leak vulnerability in Bento4's mp4fragment tool allows attackers to cause information disclosure by processing specially crafted invalid MP4 ...

Feb 19, 2025
CVE-2025-25945
6.5

This vulnerability in Bento4 v1.6.0-641 allows attackers to read sensitive information from memory through improper handling of MP4 files. It affects ...

Feb 19, 2025
CVE-2025-24408
6.5

Adobe Commerce has an information exposure vulnerability that allows low-privileged attackers to access sensitive data without user interaction. This ...

Feb 11, 2025
CVE-2025-24373
6.5

This vulnerability allows unauthorized users to access any PDF invoice or packing slip from a WooCommerce store by manipulating URL parameters. It aff...

Feb 4, 2025
CVE-2025-23047
6.5

CVE-2025-23047 is a Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability in Cilium's Hubble UI that allows malicious websites to access...

Jan 22, 2025
CVE-2025-0441
6.5

This vulnerability in Google Chrome's Fenced Frames implementation allows attackers to extract potentially sensitive system information through specia...

Jan 15, 2025
CVE-2024-10548
6.5

The WP Project Manager WordPress plugin exposes hashed passwords and other sensitive data through an insecure REST API endpoint. Authenticated attacke...

Dec 19, 2024
CVE-2024-53858
6.5

The GitHub CLI (gh) versions before 2.63.0 leak authentication tokens when cloning repositories containing git submodules from non-GitHub hosts. This ...

Nov 27, 2024
CVE-2024-52506
6.5

This vulnerability in Graylog's reporting functionality allows authorized users to potentially access other users' reports when multiple concurrent re...

Nov 18, 2024
CVE-2024-20457
6.5

This vulnerability allows authenticated remote attackers to view sensitive information, including credentials, stored in clear text within Cisco Unifi...

Nov 6, 2024
CVE-2024-22032
6.5

This vulnerability in RKE1 clusters causes continuous reconciliation when secrets encryption is enabled, exposing Kube API secret values in plaintext ...

Oct 16, 2024
CVE-2024-21205
6.5

This vulnerability in Oracle Service Bus allows authenticated attackers with low privileges to access sensitive data via HTTP requests. It affects Ora...

Oct 15, 2024
CVE-2024-43609
6.5

This Microsoft Office spoofing vulnerability allows attackers to craft malicious documents that appear legitimate to users. It affects users who open ...

Oct 8, 2024
CVE-2024-45792
6.5

An information disclosure vulnerability in Mantis Bug Tracker allows unprivileged registered users to retrieve other users' personal system profile in...

Sep 30, 2024

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,066 CVEs classified as CWE-200, with 92 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free