CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,078)
This vulnerability in zlt2000 microservices-platform exposes sensitive information through the Spring Actuator endpoint. Attackers can remotely access...
Aug 8, 2025The GiveWP WordPress plugin up to version 4.6.0 exposes donor information including names, emails, and donor IDs to unauthenticated attackers. This vu...
Aug 6, 2025This vulnerability in Exrick xboot allows remote attackers to access sensitive information through Spring Boot Admin/Spring Actuator endpoints. It aff...
Aug 4, 2025This vulnerability allows unauthorized users to access cached content from Umbraco's Content Delivery API even when API key authentication is required...
Jul 30, 2025The WoodMart WordPress theme plugin has an information exposure vulnerability that allows unauthenticated attackers to access password-protected, priv...
Jul 11, 2025Infoblox NETMRI versions before 7.6.1 contain a vulnerability that allows remote authenticated users to read arbitrary files with root-level access. T...
May 22, 2025This vulnerability in Netgear DGND3700 routers allows remote attackers to access sensitive information through the /currentsetting.htm file via the mi...
May 20, 2025This vulnerability in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0 allows remote attackers to access sensitive configurati...
May 11, 2025This vulnerability in TOTOLINK A720R routers allows remote attackers to access sensitive system configuration information without authentication. By m...
May 5, 2025This vulnerability in ScriptAndTools eCommerce-website-in-PHP 3.0 allows remote attackers to access sensitive information through the /admin/subscribe...
Apr 27, 2025The Prevent Direct Access WordPress plugin generates insufficiently random file names for protected files, allowing unauthenticated attackers to guess...
Apr 25, 2025The Memberpress WordPress plugin exposes sensitive information through WordPress core search functionality. Unauthenticated attackers can access restr...
Apr 22, 2025The WP STAGING Pro WordPress Backup Plugin has an information disclosure vulnerability that allows unauthenticated attackers to discover outdated plug...
Apr 16, 2025The Developer Toolbar WordPress plugin exposes sensitive server information through a publicly accessible phpinfo.php script. This allows unauthentica...
Apr 12, 2025This vulnerability allows unauthenticated attackers to list and delete CLI authentication tokens in SUSE Rancher before the CLI can retrieve them. Thi...
Apr 11, 2025The Accept SagePay Payments Using Contact Form 7 WordPress plugin exposes sensitive server information through a publicly accessible phpinfo.php scrip...
Apr 8, 2025The Melhor Envio WordPress plugin exposes sensitive information through a hardcoded hash in the 'run' function. Unauthenticated attackers can extract ...
Apr 8, 2025This vulnerability in Vite allows attackers to bypass file access restrictions and read arbitrary files from the server. It affects Vite 6.0+ developm...
Apr 3, 2025An attacker controlling the element.json well-known file can potentially access media encryption keys used in Element Call calls. This affects Element...
Apr 3, 2025ZITADEL's 'Ignoring unknown usernames' setting fails to properly hide user existence due to username normalization, allowing attackers to determine if...
Mar 31, 2025Vite development servers configured to expose content to the network can leak sensitive file contents through specific query parameters (?inline&impor...
Mar 31, 2025The DAP to Autoresponders Email Syncing WordPress plugin exposes sensitive server information through a publicly accessible phpinfo.php file. This all...
Mar 29, 2025This vulnerability allows remote unauthenticated attackers to obtain sensitive software version information from multiple Fortinet products by reading...
Mar 28, 2025This vulnerability in Directus allows authenticated users to enumerate database field contents they shouldn't have permission to view. By exploiting t...
Mar 26, 2025The Easy Digital Downloads WordPress plugin exposes private download post titles to unauthenticated users via an AJAX function. This affects all WordP...
Mar 25, 2025This CVE describes a path traversal vulnerability in Vite development servers where attackers can bypass file access restrictions by appending '?raw??...
Mar 24, 2025The NEX-Forms WordPress plugin up to version 8.8.1 allows unauthenticated attackers to access uploaded files due to insufficient directory listing pre...
Mar 12, 2025This CVE describes an information exposure vulnerability in QNAP NAS products that could allow remote attackers to access sensitive system information...
Mar 7, 2025The Content Control WordPress plugin up to version 2.5.0 allows unauthenticated attackers to access restricted content through WordPress core search f...
Mar 5, 2025CVE-2019-1815 allows unauthenticated attackers to access sensitive logs containing wireless pre-shared keys, VPN keys, and other privileged informatio...
Mar 4, 2025Mastodon instances with domain block visibility set to 'users' (logged-in users) inadvertently expose block reasons to unapproved users. This affects ...
Feb 27, 2025The Classified Listing WordPress plugin has an information disclosure vulnerability that allows unauthenticated attackers to extract sensitive data li...
Feb 25, 2025This vulnerability in AnkiDroid allows attackers to access and copy internal application files from protected storage to publicly accessible locations...
Feb 11, 2025The Tripetto WordPress plugin has a vulnerability that allows unauthenticated attackers to access files uploaded through forms, including potentially ...
Feb 5, 2025This vulnerability allows unauthenticated remote attackers to access sensitive information from Alpine Halo9 devices via the DLT interface on TCP port...
Jan 31, 2025This vulnerability in Umbraco CMS allows attackers to determine whether specific user accounts exist by analyzing response codes and timing difference...
Jan 21, 2025The Ultimate Member WordPress plugin versions up to 2.9.1 leak sensitive user metadata through error messages. Unauthenticated attackers can extract d...
Jan 18, 2025The Moving Users WordPress plugin exposes sensitive user data through predictable JSON file locations in export functionality. Unauthenticated attacke...
Jan 17, 2025CVE-2024-56136 is an information disclosure vulnerability in Zulip Server that allows unauthenticated attackers to determine if specific email address...
Jan 16, 2025This vulnerability in D-Link DIR-878 routers allows remote attackers to access sensitive information through the /dllog.cgi endpoint via HTTP POST req...
Jan 15, 2025The W3 Total Cache WordPress plugin exposes debug log files publicly when debug mode is enabled, allowing unauthenticated attackers to view potentiall...
Jan 14, 2025This vulnerability in reggie 1.0 allows remote attackers to obtain sensitive information by manipulating the 'code' parameter in the phone number vali...
Jan 13, 2025The Member Access WordPress plugin up to version 1.1.6 allows unauthenticated attackers to bypass content restrictions via WordPress core search funct...
Jan 7, 2025This CVE describes an information exposure vulnerability in Mashov software where sensitive data is accessible to unauthorized actors. The vulnerabili...
Dec 30, 2024This vulnerability in Amcrest IP cameras allows remote attackers to access sensitive information through the web interface. It affects multiple Amcres...
Dec 27, 2024The Page Restriction WordPress plugin (versions up to 1.3.6) allows unauthenticated attackers to access sensitive content from posts/pages restricted ...
Dec 20, 2024The Simple Page Access Restriction WordPress plugin exposes sensitive content through WordPress's built-in search feature. Unauthenticated attackers c...
Dec 18, 2024The Accept Authorize.NET Payments Using Contact Form 7 WordPress plugin exposes configuration data through the cf7adn-info.php file, allowing unauthen...
Dec 18, 2024An information disclosure vulnerability in Fortra's GoAnywhere MFT allows external attackers to access sensitive admin root folder resources without a...
Dec 13, 2024The Restrict Content plugin for WordPress (versions up to 2.2.8) allows unauthenticated attackers to access sensitive content from posts restricted to...
Dec 11, 2024About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,078 CVEs classified as CWE-200, with 96 rated critical and 397 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.6.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free