CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,069
Total CVEs
93
Critical
391
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
133
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,069)

CVE-2025-43495
5.4

This vulnerability allows malicious iOS/iPadOS apps to monitor keystrokes without user permission, potentially capturing sensitive input like password...

Nov 4, 2025
CVE-2024-42486
5.4

A vulnerability in Cilium's GatewayAPI controller fails to properly propagate ReferenceGrant changes, allowing Gateway resources to retain access to s...

Aug 16, 2024
CVE-2026-29787
5.3

mcp-memory-service versions before 10.21.0 expose detailed system information via an unauthenticated /api/health/detailed endpoint when MCP_ALLOW_ANON...

Mar 7, 2026
CVE-2026-30829
5.3

This vulnerability allows unauthenticated attackers to access unpublished status pages and internal monitoring data in Checkmate installations. Any or...

Mar 7, 2026
CVE-2026-28434
5.3

This vulnerability in cpp-httplib leaks internal exception messages to unauthenticated clients when request handlers throw C++ exceptions. Any applica...

Mar 4, 2026
CVE-2026-28559
5.3

wpForo Forum 2.4.14 contains an information disclosure vulnerability where unauthenticated attackers can access private and unapproved forum topics th...

Feb 28, 2026
CVE-2026-2975
5.3

FastApiAdmin up to version 2.2.0 contains an information disclosure vulnerability in the reset_api_docs function of the custom documentation endpoint....

Feb 23, 2026
CVE-2026-2894
5.3

This vulnerability in funadmin allows remote attackers to exploit the getMember function in the forget.html login component to disclose sensitive info...

Feb 21, 2026
CVE-2026-2861
5.3

This vulnerability in Foswiki allows remote attackers to access sensitive information through the Changes/Viewfile/Oops component. It affects all Fosw...

Feb 21, 2026
CVE-2025-13113
5.3

The Web Accessibility by accessiBe WordPress plugin exposes sensitive configuration data to unauthenticated users via browser console logging. This vu...

Feb 19, 2026
CVE-2025-12074
5.3

The Context Blog WordPress theme has an information disclosure vulnerability that allows unauthenticated attackers to access password-protected, priva...

Feb 18, 2026
CVE-2026-21722
5.3

This vulnerability in Grafana allows attackers to view annotation data outside the locked timerange on public dashboards with annotations enabled. Org...

Feb 12, 2026
CVE-2026-20682
5.3

A logic flaw in iOS/iPadOS note management could allow attackers to access users' deleted notes. This affects users running vulnerable versions of iOS...

Feb 11, 2026
CVE-2024-26479
5.3

This vulnerability in Statping-ng v0.91.0 allows attackers to access sensitive information through crafted requests to the command execution function....

Feb 11, 2026
CVE-2024-26478
5.3

This vulnerability in Statping-ng v0.91.0 allows attackers to retrieve sensitive user information through unauthorized API requests to the /api/users ...

Feb 11, 2026
CVE-2026-2148
5.3

This vulnerability in Tenda AC21 routers allows remote attackers to access sensitive information through the web management interface. Attackers can e...

Feb 8, 2026
CVE-2026-2147
5.3

This vulnerability in Tenda AC21 routers allows remote attackers to access sensitive information through the web management interface. Attackers can e...

Feb 8, 2026
CVE-2026-2207
5.3

This vulnerability in WeKan versions up to 8.20 allows remote attackers to access sensitive information through the Activity Publication Handler compo...

Feb 8, 2026
CVE-2026-2056
5.3

This vulnerability in D-Link DIR-605L and DIR-619L routers allows remote attackers to access sensitive information through the DHCP Connection Status ...

Feb 6, 2026
CVE-2026-2054
5.3

A security vulnerability in D-Link DIR-605L and DIR-619L routers allows remote attackers to access sensitive information through the Wifi Setting Hand...

Feb 6, 2026
CVE-2026-2055
5.3

A vulnerability in D-Link DIR-605L and DIR-619L routers allows remote attackers to disclose sensitive information via the DHCP Client Information Hand...

Feb 6, 2026
CVE-2026-25523
5.3

This vulnerability allows attackers to discover the Magento admin URL without prior knowledge by exploiting the X-Original-Url header in certain confi...

Feb 4, 2026
CVE-2025-15482
5.3

The Chapa Payment Gateway Plugin for WooCommerce exposes sensitive merchant API keys through an unauthenticated WooCommerce API endpoint. This vulnera...

Feb 4, 2026
CVE-2025-15508
5.3

The Magic Import Document Extractor WordPress plugin exposes the site's magicimport.ai license key in page source code through the get_frontend_settin...

Feb 4, 2026
CVE-2026-1371
5.3

This vulnerability in Tutor LMS WordPress plugin allows authenticated attackers with Subscriber-level access or higher to retrieve sensitive coupon in...

Feb 3, 2026
CVE-2026-0950
5.3

The Spectra Gutenberg Blocks plugin for WordPress has an information disclosure vulnerability that allows unauthenticated attackers to read excerpts f...

Feb 3, 2026
CVE-2026-24473
5.3

This vulnerability in Hono's static middleware for Cloudflare Workers allows attackers to read arbitrary environment keys by manipulating file paths. ...

Jan 27, 2026
CVE-2026-24422
5.3

This vulnerability in phpMyFAQ exposes sensitive user information through multiple public API endpoints due to insufficient access controls. Attackers...

Jan 24, 2026
CVE-2026-21974
5.3

This vulnerability in Oracle Life Sciences Central Designer allows unauthenticated attackers to read sensitive data via HTTP requests. It affects vers...

Jan 20, 2026
CVE-2026-21928
5.3

This vulnerability in Oracle Solaris 11 kernel allows unauthenticated attackers with network access via TCP to read sensitive system data. It affects ...

Jan 20, 2026
CVE-2026-1194
5.3

A security vulnerability in MineAdmin 1.x/2.x allows remote attackers to exploit the Swagger component to disclose sensitive information. This affects...

Jan 20, 2026
CVE-2026-1175
5.3

This vulnerability in birkir prime's GraphQL Directive Handler allows remote attackers to extract sensitive information through error messages. It aff...

Jan 19, 2026
CVE-2026-1170
5.3

This vulnerability in birkir prime's GraphQL API allows remote attackers to access sensitive information through manipulation of the /graphql endpoint...

Jan 19, 2026
CVE-2025-12129
5.3

The CubeWP WordPress plugin has an information exposure vulnerability that allows unauthenticated attackers to access password-protected, private, or ...

Jan 17, 2026
CVE-2025-14075
5.3

The WP Hotel Booking WordPress plugin exposes sensitive customer information to unauthenticated attackers. By providing a valid email address and a pu...

Jan 17, 2026
CVE-2025-24089
5.3

This CVE describes a permissions vulnerability in iOS/iPadOS that allows malicious apps to enumerate which other apps are installed on a user's device...

Jan 16, 2026
CVE-2026-22645
5.3

This vulnerability allows unauthenticated attackers to view detailed information about all software components, versions, and licenses used by the app...

Jan 15, 2026
CVE-2026-0717
5.3

The LottieFiles WordPress plugin exposes sensitive account credentials through an unauthenticated REST API endpoint. Unauthenticated attackers can ret...

Jan 14, 2026
CVE-2025-14464
5.3

The PDF Resume Parser WordPress plugin exposes SMTP credentials to unauthenticated users through an insecure AJAX endpoint. This allows attackers to s...

Jan 14, 2026
CVE-2026-0888
5.3

This CVE describes an information disclosure vulnerability in the XML component of Firefox and Thunderbird. It allows attackers to potentially access ...

Jan 13, 2026
CVE-2026-0883
5.3

This CVE describes an information disclosure vulnerability in the Networking component of Mozilla products. It allows attackers to potentially access ...

Jan 13, 2026
CVE-2025-14507
5.3

The EventPrime WordPress plugin exposes sensitive booking data through its REST API to unauthenticated attackers when the API is enabled. This vulnera...

Jan 13, 2026
CVE-2026-22251
5.3

CVE-2026-22251 is a vulnerability in the wlc Weblate command-line client where unscoped API keys could be inadvertently leaked to different servers. T...

Jan 12, 2026
CVE-2026-20027
5.3

A buffer out-of-bounds read vulnerability in Cisco Snort 3's DCE/RPC request processing allows unauthenticated remote attackers to cause information d...

Jan 7, 2026
CVE-2025-68273
5.3

Signal K Server versions before 2.19.0 have an unauthenticated information disclosure vulnerability that allows any user to retrieve sensitive system ...

Jan 1, 2026
CVE-2025-14280
5.3

The PixelYourSite WordPress plugin exposes sensitive information through publicly accessible log files when the 'Meta API logs' setting is enabled. Un...

Dec 29, 2025
CVE-2025-15082
5.3

This vulnerability in TOZED ZLT M30s routers allows remote attackers to disclose sensitive information by manipulating the 'goformId' parameter in the...

Dec 25, 2025
CVE-2025-12492
5.3

This vulnerability allows unauthenticated attackers to extract sensitive user information from WordPress sites using the Ultimate Member plugin. Attac...

Dec 20, 2025
CVE-2025-12408
5.3

This vulnerability in the WordPress Events Manager plugin allows unauthenticated attackers to access sensitive event location data that should be prot...

Dec 12, 2025
CVE-2025-13660
5.3

The Guest Support WordPress plugin up to version 1.2.3 contains an unauthenticated user email disclosure vulnerability. Attackers can exploit a public...

Dec 12, 2025

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,069 CVEs classified as CWE-200, with 93 rated critical and 391 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free