CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,068)
This vulnerability allows an authenticated attacker on a Windows system to access sensitive kernel information they shouldn't have access to. It affec...
Aug 12, 2025This vulnerability in Windows User-Mode Driver Framework Host allows local attackers to access sensitive information they shouldn't have permission to...
Jul 8, 2025This Windows Kernel vulnerability allows an authenticated attacker with local access to a system to read sensitive information they shouldn't have acc...
Jul 8, 2025Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier contain an information exposure vulnerability that could allow attackers ...
Jun 10, 2025A permissions vulnerability in macOS allows applications to access sensitive location information without proper authorization. This affects macOS sys...
May 29, 2025This vulnerability in Intel Tiber Edge Platform's Edge Orchestrator software allows authenticated users with local access to potentially access sensit...
May 13, 2025This vulnerability in Visual Studio allows authenticated local attackers to bypass access controls and access sensitive information they shouldn't hav...
May 13, 2025This CVE describes an information disclosure vulnerability in macOS where applications could access sensitive user data without proper authorization. ...
May 12, 2025This CVE describes a privacy vulnerability in Apple operating systems where applications could access sensitive user data from log entries. The issue ...
May 12, 2025This CVE describes an information disclosure vulnerability in Apple operating systems where an app could leak sensitive kernel state. It affects multi...
May 12, 2025This CVE describes a permissions vulnerability in iOS/iPadOS that allows apps to read persistent device identifiers without proper authorization. This...
May 12, 2025This CVE describes an information exposure vulnerability in Adobe ColdFusion that allows low-privileged local attackers to access sensitive informatio...
Apr 8, 2025This CVE describes an information disclosure vulnerability in Apple operating systems where an app could access sensitive user data due to improper st...
Mar 31, 2025A macOS vulnerability allows malicious applications to access private information due to insufficient access controls. This affects macOS Sequoia befo...
Mar 31, 2025This vulnerability allows malicious apps to bypass data container restrictions and access sensitive user data on Apple devices. It affects iOS, iPadOS...
Mar 31, 2025This CVE describes an information disclosure vulnerability in Apple operating systems where improper logging sanitization allows applications to acces...
Mar 31, 2025A macOS vulnerability allows sandboxed applications to access sensitive user data from system logs. This affects macOS systems running versions before...
Mar 31, 2025This CVE describes a macOS sandbox escape vulnerability that allows malicious applications to bypass security restrictions and access sensitive user d...
Mar 31, 2025This CVE describes a library injection vulnerability in macOS that allows applications to bypass file system protections and modify restricted areas. ...
Mar 31, 2025This macOS vulnerability allows applications to bypass file system protection mechanisms and modify protected areas. It affects macOS Ventura, Sequoia...
Mar 31, 2025This vulnerability allows attackers to leak process memory by tricking users into processing malicious font files. It affects macOS, iOS, iPadOS, and ...
Mar 31, 2025This vulnerability in Xcode allows malicious applications to access private information they shouldn't have permission to view. It affects developers ...
Mar 31, 2025This vulnerability in Icinga Director allows authenticated users with API access to bypass object-level restrictions and retrieve or modify configurat...
Mar 26, 2025This macOS vulnerability allows malicious applications to access removable storage devices (like USB drives) without user permission. It affects macOS...
Mar 10, 2025This CVE describes an information disclosure vulnerability in Apple operating systems where a local user could potentially access sensitive user infor...
Mar 10, 2025This CVE describes an information disclosure vulnerability in macOS where applications can access user-sensitive data without proper authorization. Th...
Jan 27, 2025A macOS vulnerability allows malicious applications to leak sensitive user information due to improper state management. This affects users running ma...
Jan 27, 2025This vulnerability in macOS allows applications to bypass security checks and access protected user data they shouldn't have permission to view. It af...
Jan 27, 2025This vulnerability allows any authenticated user in Coolify to access sensitive GitHub/GitLab configuration details (client ID, client secret, webhook...
Jan 24, 2025This vulnerability allows a malicious Android app to hide a notification listener service (NLS) from the device's Settings menu due to a logic error i...
Jan 21, 2025CVE-2023-40108 is an Android vulnerability that allows unauthorized access to another user's media content due to missing permission checks. This coul...
Jan 21, 2025This vulnerability allows local attackers to view thumbnail images of deleted photos on Android devices due to a confused deputy issue in the MiniThum...
Jan 17, 2025CVE-2025-21615 allows malicious apps on the same Android device to exfiltrate sensitive GPS tracking data from the AAT (Another Activity Tracker) appl...
Jan 6, 2025CVE-2021-26281 is an information disclosure vulnerability in Vivo alarm clock modules where improperly stored parameters leak sensitive information. T...
Dec 17, 2024This CVE allows local low-privileged users on Juniper SRX Series devices to access protected files containing sensitive information through crafted CL...
Oct 11, 2024This macOS vulnerability allows applications to read sensitive location information due to improper handling of temporary files. It affects macOS Vent...
Sep 17, 2024This CVE describes a macOS sandbox escape vulnerability where applications could bypass sandbox restrictions to access protected user data. It affects...
Sep 17, 2024This macOS vulnerability allows applications to leak sensitive user information due to insufficient access controls. It affects macOS Ventura versions...
Sep 17, 2024This macOS vulnerability allows applications to access sensitive user data due to improper environment variable validation. It affects macOS systems b...
Sep 17, 2024This vulnerability allows iOS/iPadOS apps to leak sensitive user information due to insufficient data protection. It affects users running vulnerable ...
Sep 17, 2024This vulnerability in Cisco Duo Epic for Hyperdrive allows authenticated local attackers to view sensitive information stored unencrypted in a registr...
Sep 4, 2024This CVE describes a macOS vulnerability where applications can access sensitive user data without proper authorization. It affects macOS Sonoma, Mont...
Jul 29, 2024This CVE describes an information disclosure vulnerability in Apple operating systems where an app could access user-sensitive data without proper aut...
Jul 29, 2024This CVE describes an information disclosure vulnerability in macOS where a malicious application could access private information. The vulnerability ...
Jul 29, 2024CVE-2024-38041 is a Windows kernel information disclosure vulnerability that allows attackers to read sensitive kernel memory contents. This affects W...
Jul 9, 2024This vulnerability in Windows Cryptographic Services allows an attacker to read sensitive information from memory that should be protected. It affects...
Jun 11, 2024This vulnerability allows authenticated attackers on FortiWeb web application firewalls to read password hashes of other administrators through CLI co...
Jun 3, 2024This Windows kernel vulnerability allows authenticated attackers to read kernel memory contents, potentially exposing sensitive information like passw...
Aug 14, 2019This Windows GDI vulnerability allows attackers to read sensitive memory contents, potentially exposing system information that could enable further a...
Aug 14, 2019This vulnerability allows malicious iOS/iPadOS apps to monitor keystrokes without user permission, potentially capturing sensitive input like password...
Nov 4, 2025About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,068 CVEs classified as CWE-200, with 93 rated critical and 390 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free