CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,067)
This vulnerability in Intel Tiber Edge Platform's Edge Orchestrator software allows authenticated users on adjacent networks to access sensitive infor...
May 13, 2025This CVE describes a privilege escalation vulnerability in Splunk Enterprise and Cloud Platform where low-privileged users can bypass SPL safeguards f...
Mar 26, 2025This vulnerability allows low-privileged Splunk users to bypass SPL safeguards for risky commands by tricking higher-privileged users into executing m...
Mar 26, 2025This vulnerability in the Responsive Addons for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to e...
Mar 26, 2025This vulnerability allows low-privileged Splunk users to bypass command safeguards by tricking higher-privileged users into executing saved searches c...
Dec 10, 2024This vulnerability in the Essential Addons for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to ex...
Nov 15, 2024This vulnerability allows unauthenticated attackers to access system logs through the web management interface, exposing sensitive credentials and con...
Nov 5, 2024This vulnerability in Lobe Chat allows authenticated attackers to steal backend API keys by manipulating frontend base URLs to redirect requests to at...
Jun 17, 2024This vulnerability in Microsoft Dynamics 365 (On-Premises) allows an authenticated attacker to access sensitive information they shouldn't have permis...
Jun 11, 2024CVE-2019-1171 is an information disclosure vulnerability in SymCrypt's OAEP decryption implementation. Attackers with local access can exploit this to...
Aug 14, 2019This CVE describes an authorization vulnerability in iOS and iPadOS that allows malicious apps to bypass access controls and read sensitive user data....
Feb 11, 2026This macOS vulnerability allows applications to access sensitive user data due to insufficient data protection. It affects macOS Tahoe versions before...
Feb 11, 2026This macOS vulnerability allows malicious applications to access notifications from other iCloud devices, potentially exposing sensitive information. ...
Feb 11, 2026This macOS vulnerability allows applications to access sensitive user data due to insufficient data redaction in logging. It affects macOS Sequoia bef...
Feb 11, 2026A permissions vulnerability in macOS allowed applications to access protected user data they shouldn't have been able to access. This affects macOS sy...
Feb 11, 2026This macOS vulnerability allows applications to bypass privacy controls and access sensitive user data without proper authorization. It affects macOS ...
Feb 11, 2026This vulnerability allows an authorized attacker with local access to a Windows system to access sensitive information through Windows File Explorer. ...
Jan 13, 2026This vulnerability in Windows File Explorer allows an authorized attacker with local access to a system to access sensitive information they shouldn't...
Jan 13, 2026This vulnerability allows an authorized attacker with local access to a Windows system to access sensitive information through Windows File Explorer. ...
Jan 13, 2026This vulnerability in Windows Management Services allows an authenticated attacker to access sensitive information from the local system. It affects W...
Jan 13, 2026This vulnerability allows an authorized attacker with local access to a Windows system to access sensitive information through the Tablet Windows User...
Jan 13, 2026This vulnerability allows an authorized attacker with local access to a Windows system to access sensitive information through Windows File Explorer. ...
Jan 13, 2026This vulnerability in Desktop Windows Manager allows an authorized attacker with local access to disclose sensitive information from the system. It af...
Jan 13, 2026This vulnerability allows information disclosure when a weak hashed value is returned to userland code in response to an IOCTL call to obtain a sessio...
Jan 7, 2026This vulnerability in Gmission Web Fax allows unauthorized actors to access sensitive information due to missing authorization checks. It affects Web ...
Dec 29, 2025This vulnerability in Sciter's video rendering function allows a local attacker to access sensitive information through the adopt component. It affect...
Dec 26, 2025A macOS vulnerability allows applications to bypass cache protections and access sensitive user data they shouldn't have permission to view. This affe...
Dec 17, 2025A logic vulnerability in macOS allows applications to access sensitive user data due to insufficient validation. This affects macOS systems before ver...
Dec 17, 2025This macOS vulnerability allows applications to bypass security protections and access sensitive user data they shouldn't normally have permission to ...
Dec 17, 2025This vulnerability in Hitron HI3120 routers allows a local attacker to access sensitive information through the logout function on the index.html page...
Dec 15, 2025A macOS permissions vulnerability allows applications to access sensitive user data they shouldn't have permission to view. This affects macOS systems...
Dec 12, 2025This vulnerability allows an app to access sensitive user data on Apple devices due to insufficient access controls. It affects macOS, iOS, and iPadOS...
Dec 12, 2025A macOS vulnerability allows applications to access sensitive user data due to improper state management. This affects macOS Tahoe versions before 26....
Dec 12, 2025This macOS vulnerability allows applications to access sensitive user data they shouldn't have permission to view. It affects macOS users running vuln...
Dec 12, 2025This vulnerability in Microsoft Office Excel allows an unauthorized local attacker to access sensitive information from Excel files. It affects users ...
Nov 11, 2025This CVE describes an information disclosure vulnerability in macOS where applications could access sensitive user data due to insufficient entitlemen...
Nov 4, 2025This CVE describes a privacy vulnerability in Apple operating systems where applications could access sensitive user data through improper handling of...
Nov 4, 2025A permissions vulnerability in macOS allows applications to access sensitive user data they shouldn't have permission to view. This affects macOS syst...
Nov 4, 2025This CVE describes a UI vulnerability in iOS/iPadOS where password fields may be unintentionally revealed, potentially exposing sensitive credentials....
Nov 4, 2025This vulnerability allows an application to access sensitive user data due to insufficient access controls. It affects multiple Apple operating system...
Nov 4, 2025This vulnerability in Microsoft Failover Cluster Virtual Driver allows an authenticated attacker with local access to a vulnerable system to read sens...
Oct 14, 2025This Windows Kernel vulnerability allows an authenticated attacker with local access to a system to read sensitive information from kernel memory. It ...
Oct 14, 2025This vulnerability allows an authorized attacker with local access to a Windows High Availability Services system to access sensitive information they...
Oct 14, 2025This Windows Kernel vulnerability allows a local authenticated attacker to access sensitive information they shouldn't have permission to view. It aff...
Oct 14, 2025This macOS vulnerability allows applications to access protected user data they shouldn't have permission to view. It affects macOS systems before Son...
Sep 15, 2025This Windows Kernel vulnerability allows an authenticated attacker with local access to a system to read sensitive information they shouldn't have acc...
Sep 9, 2025This vulnerability in Android's Bluetooth file sharing component allows unauthorized access to files across user profiles on the same device. It affec...
Sep 4, 2025This vulnerability allows authenticated local attackers on affected Cisco devices to access sensitive information like stored credentials through impr...
Aug 27, 2025This vulnerability in the Storage Port Driver allows an authenticated attacker with local access to a system to read sensitive information they should...
Aug 12, 2025This vulnerability allows an authenticated attacker on a Windows system to access sensitive kernel information they shouldn't have access to. It affec...
Aug 12, 2025About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,067 CVEs classified as CWE-200, with 92 rated critical and 390 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free