CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,078
Total CVEs
96
Critical
397
High
6.6
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
133
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 26
5 Oracle 20
6 Google 15
7 Debian 12
8 Mozilla 10
9 Netgear 9
10 Splunk 9

All Information Exposure CVEs (1,078)

CVE-2025-8738
5.3

This vulnerability in zlt2000 microservices-platform exposes sensitive information through the Spring Actuator endpoint. Attackers can remotely access...

Aug 8, 2025
CVE-2025-8620
5.3

The GiveWP WordPress plugin up to version 4.6.0 exposes donor information including names, emails, and donor IDs to unauthenticated attackers. This vu...

Aug 6, 2025
CVE-2025-8525
5.3

This vulnerability in Exrick xboot allows remote attackers to access sensitive information through Spring Boot Admin/Spring Actuator endpoints. It aff...

Aug 4, 2025
CVE-2025-54425
5.3

This vulnerability allows unauthorized users to access cached content from Umbraco's Content Delivery API even when API key authentication is required...

Jul 30, 2025
CVE-2025-6745
5.3

The WoodMart WordPress theme plugin has an information exposure vulnerability that allows unauthenticated attackers to access password-protected, priv...

Jul 11, 2025
CVE-2024-54188
5.3

Infoblox NETMRI versions before 7.6.1 contain a vulnerability that allows remote authenticated users to read arbitrary files with root-level access. T...

May 22, 2025
CVE-2025-4980
5.3

This vulnerability in Netgear DGND3700 routers allows remote attackers to access sensitive information through the /currentsetting.htm file via the mi...

May 20, 2025
CVE-2025-4535
5.3

This vulnerability in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0 allows remote attackers to access sensitive configurati...

May 11, 2025
CVE-2025-4270
5.3

This vulnerability in TOTOLINK A720R routers allows remote attackers to access sensitive system configuration information without authentication. By m...

May 5, 2025
CVE-2025-3975
5.3

This vulnerability in ScriptAndTools eCommerce-website-in-PHP 3.0 allows remote attackers to access sensitive information through the /admin/subscribe...

Apr 27, 2025
CVE-2025-3923
5.3

The Prevent Direct Access WordPress plugin generates insufficiently random file names for protected files, allowing unauthenticated attackers to guess...

Apr 25, 2025
CVE-2024-11299
5.3

The Memberpress WordPress plugin exposes sensitive information through WordPress core search functionality. Unauthenticated attackers can access restr...

Apr 22, 2025
CVE-2025-3104
5.3

The WP STAGING Pro WordPress Backup Plugin has an information disclosure vulnerability that allows unauthenticated attackers to discover outdated plug...

Apr 16, 2025
CVE-2025-2881
5.3

The Developer Toolbar WordPress plugin exposes sensitive server information through a publicly accessible phpinfo.php script. This allows unauthentica...

Apr 12, 2025
CVE-2025-23387
5.3

This vulnerability allows unauthenticated attackers to list and delete CLI authentication tokens in SUSE Rancher before the CLI can retrieve them. Thi...

Apr 11, 2025
CVE-2025-2883
5.3

The Accept SagePay Payments Using Contact Form 7 WordPress plugin exposes sensitive server information through a publicly accessible phpinfo.php scrip...

Apr 8, 2025
CVE-2024-13820
5.3

The Melhor Envio WordPress plugin exposes sensitive information through a hardcoded hash in the 'run' function. Unauthenticated attackers can extract ...

Apr 8, 2025
CVE-2025-31486
5.3

This vulnerability in Vite allows attackers to bypass file access restrictions and read arbitrary files from the server. It affects Vite 6.0+ developm...

Apr 3, 2025
CVE-2025-31126
5.3

An attacker controlling the element.json well-known file can potentially access media encryption keys used in Element Call calls. This affects Element...

Apr 3, 2025
CVE-2025-31124
5.3

ZITADEL's 'Ignoring unknown usernames' setting fails to properly hide user existence due to username normalization, allowing attackers to determine if...

Mar 31, 2025
CVE-2025-31125
KEV EPSS 66% 5.3

Vite development servers configured to expose content to the network can leak sensitive file contents through specific query parameters (?inline&impor...

Mar 31, 2025
CVE-2025-2840
5.3

The DAP to Autoresponders Email Syncing WordPress plugin exposes sensitive server information through a publicly accessible phpinfo.php file. This all...

Mar 29, 2025
CVE-2021-24008
5.3

This vulnerability allows remote unauthenticated attackers to obtain sensitive software version information from multiple Fortinet products by reading...

Mar 28, 2025
CVE-2025-30352
5.3

This vulnerability in Directus allows authenticated users to enumerate database field contents they shouldn't have permission to view. By exploiting t...

Mar 26, 2025
CVE-2025-2252
5.3

The Easy Digital Downloads WordPress plugin exposes private download post titles to unauthenticated users via an AJAX function. This affects all WordP...

Mar 25, 2025
CVE-2025-30208
EPSS 88.1% 5.3

This CVE describes a path traversal vulnerability in Vite development servers where attackers can bypass file access restrictions by appending '?raw??...

Mar 24, 2025
CVE-2024-13498
5.3

The NEX-Forms WordPress plugin up to version 8.8.1 allows unauthenticated attackers to access uploaded files due to insufficient directory listing pre...

Mar 12, 2025
CVE-2024-13086
5.3

This CVE describes an information exposure vulnerability in QNAP NAS products that could allow remote attackers to access sensitive system information...

Mar 7, 2025
CVE-2024-11153
5.3

The Content Control WordPress plugin up to version 2.5.0 allows unauthenticated attackers to access restricted content through WordPress core search f...

Mar 5, 2025
CVE-2019-1815
5.3

CVE-2019-1815 allows unauthenticated attackers to access sensitive logs containing wireless pre-shared keys, VPN keys, and other privileged informatio...

Mar 4, 2025
CVE-2025-27399
5.3

Mastodon instances with domain block visibility set to 'users' (logged-in users) inadvertently expose block reasons to unapproved users. This affects ...

Feb 27, 2025
CVE-2025-1063
5.3

The Classified Listing WordPress plugin has an information disclosure vulnerability that allows unauthenticated attackers to extract sensitive data li...

Feb 25, 2025
CVE-2024-44336
5.3

This vulnerability in AnkiDroid allows attackers to access and copy internal application files from protected storage to publicly accessible locations...

Feb 11, 2025
CVE-2024-13829
5.3

The Tripetto WordPress plugin has a vulnerability that allows unauthenticated attackers to access files uploaded through forms, including potentially ...

Feb 5, 2025
CVE-2024-23962
5.3

This vulnerability allows unauthenticated remote attackers to access sensitive information from Alpine Halo9 devices via the DLT interface on TCP port...

Jan 31, 2025
CVE-2025-24011
EPSS 19.3% 5.3

This vulnerability in Umbraco CMS allows attackers to determine whether specific user accounts exist by analyzing response codes and timing difference...

Jan 21, 2025
CVE-2025-0318
5.3

The Ultimate Member WordPress plugin versions up to 2.9.1 leak sensitive user metadata through error messages. Unauthenticated attackers can extract d...

Jan 18, 2025
CVE-2024-12637
5.3

The Moving Users WordPress plugin exposes sensitive user data through predictable JSON file locations in export functionality. Unauthenticated attacke...

Jan 17, 2025
CVE-2024-56136
5.3

CVE-2024-56136 is an information disclosure vulnerability in Zulip Server that allows unauthenticated attackers to determine if specific email address...

Jan 16, 2025
CVE-2025-0481
5.3

This vulnerability in D-Link DIR-878 routers allows remote attackers to access sensitive information through the /dllog.cgi endpoint via HTTP POST req...

Jan 15, 2025
CVE-2024-12008
EPSS 37.8% 5.3

The W3 Total Cache WordPress plugin exposes debug log files publicly when debug mode is enabled, allowing unauthenticated attackers to view potentiall...

Jan 14, 2025
CVE-2025-0403
5.3

This vulnerability in reggie 1.0 allows remote attackers to obtain sensitive information by manipulating the 'code' parameter in the phone number vali...

Jan 13, 2025
CVE-2024-11290
5.3

The Member Access WordPress plugin up to version 1.1.6 allows unauthenticated attackers to bypass content restrictions via WordPress core search funct...

Jan 7, 2025
CVE-2024-47923
5.3

This CVE describes an information exposure vulnerability in Mashov software where sensitive data is accessible to unauthorized actors. The vulnerabili...

Dec 30, 2024
CVE-2024-12984
5.3

This vulnerability in Amcrest IP cameras allows remote attackers to access sensitive information through the web interface. It affects multiple Amcres...

Dec 27, 2024
CVE-2024-11297
5.3

The Page Restriction WordPress plugin (versions up to 1.3.6) allows unauthenticated attackers to access sensitive content from posts/pages restricted ...

Dec 20, 2024
CVE-2024-11295
5.3

The Simple Page Access Restriction WordPress plugin exposes sensitive content through WordPress's built-in search feature. Unauthenticated attackers c...

Dec 18, 2024
CVE-2024-12250
5.3

The Accept Authorize.NET Payments Using Contact Form 7 WordPress plugin exposes configuration data through the cf7adn-info.php file, allowing unauthen...

Dec 18, 2024
CVE-2024-9945
5.3

An information disclosure vulnerability in Fortra's GoAnywhere MFT allows external attackers to access sensitive admin root folder resources without a...

Dec 13, 2024
CVE-2024-11351
5.3

The Restrict Content plugin for WordPress (versions up to 2.2.8) allows unauthenticated attackers to access sensitive content from posts restricted to...

Dec 11, 2024

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,078 CVEs classified as CWE-200, with 96 rated critical and 397 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.6.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free