CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,079
Total CVEs
96
Critical
398
High
6.6
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
133
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 26
5 Oracle 20
6 Google 15
7 Debian 12
8 Mozilla 10
9 Netgear 9
10 Splunk 9

All Information Exposure CVEs (1,079)

CVE-2024-11351
5.3

The Restrict Content plugin for WordPress (versions up to 2.2.8) allows unauthenticated attackers to access sensitive content from posts restricted to...

Dec 11, 2024
CVE-2024-11083
5.3

The ProfilePress WordPress plugin exposes sensitive information through WordPress core search functionality. Unauthenticated attackers can access rest...

Nov 27, 2024
CVE-2024-11088
5.3

The Simple Membership WordPress plugin exposes sensitive information through WordPress core search functionality. Unauthenticated attackers can access...

Nov 21, 2024
CVE-2022-20648
5.3

This vulnerability in Cisco RCM for StarOS Software allows unauthenticated remote attackers to connect to a debug service and execute debug commands, ...

Nov 15, 2024
CVE-2024-10916
5.3

This vulnerability allows remote attackers to access sensitive information through an unauthenticated HTTP GET request to /xml/info.xml on affected D-...

Nov 6, 2024
CVE-2024-33603
5.3

The LevelOne WBR-6012 router has an information disclosure vulnerability that allows unauthenticated users to access a verbose system log page contain...

Oct 30, 2024
CVE-2024-33626
5.3

The LevelOne WBR-6012 router has an information disclosure vulnerability where unauthenticated attackers can access a hidden web page that reveals the...

Oct 30, 2024
CVE-2024-10290
5.3

This vulnerability in ZZCMS 2023 allows remote attackers to access sensitive information through the file 3/qq-connect2.0/API/com/inc.php. The informa...

Oct 23, 2024
CVE-2024-8852
5.3

The All-in-One WP Migration and Backup plugin for WordPress exposes sensitive information through publicly accessible log files. Unauthenticated attac...

Oct 22, 2024
CVE-2017-20194
5.3

The Formidable Form Builder plugin for WordPress has an unauthenticated data exposure vulnerability that allows attackers to export all form entries w...

Oct 16, 2024
CVE-2024-9546
5.3

The WPIDE plugin for WordPress discloses the full server path to unauthenticated attackers due to improper error handling in the PHP-Parser library. T...

Oct 15, 2024
CVE-2024-47344
5.3

The uListing WordPress plugin versions up to 2.1.5 expose sensitive information to unauthorized actors. This vulnerability allows attackers to access ...

Oct 7, 2024
CVE-2024-7426
5.3

The PeepSo WordPress plugin discloses full server path information to unauthenticated attackers through error messages in the sse.php file. This vulne...

Sep 25, 2024
CVE-2024-7415
5.3

The Remember Me Controls WordPress plugin up to version 2.0.1 allows unauthenticated attackers to retrieve the full server path via direct access to b...

Sep 6, 2024
CVE-2024-3679
5.3

The Premium SEO Pack WordPress plugin exposes sensitive information from password-protected posts through social meta data. Unauthenticated attackers ...

Aug 29, 2024
CVE-2024-43264
5.3

The Mediavine Create WordPress plugin versions up to 1.9.8 contain an information disclosure vulnerability that allows unauthorized actors to access s...

Aug 26, 2024
CVE-2024-43258
5.3

Store Locator Plus WordPress plugin versions up to 2311.17.01 expose sensitive information to unauthorized actors. This vulnerability allows attackers...

Aug 26, 2024
CVE-2023-48957
5.3

The PureVPN Linux client 2.0.2-Productions fails to properly route DNS queries through the VPN tunnel, allowing DNS requests to leak to ISP or default...

Aug 25, 2024
CVE-2024-6499
5.3

The MaxButtons WordPress plugin exposes full server path information to unauthenticated attackers in versions up to 9.7.8. This information disclosure...

Aug 24, 2024
CVE-2024-7842
5.3

This vulnerability in SourceCodester Online Graduate Tracer System 1.0 allows remote attackers to access sensitive information through the /tracking/a...

Aug 15, 2024
CVE-2024-7411
5.3

The Newsletters plugin for WordPress has a full path disclosure vulnerability that allows unauthenticated attackers to retrieve the web application's ...

Aug 15, 2024
CVE-2024-38749
5.3

The Olive One Click Demo Import WordPress plugin versions up to 1.1.2 contains an access control vulnerability that allows unauthorized users to acces...

Aug 13, 2024
CVE-2024-38756
5.3

This vulnerability in the Weblizar Coming Soon WordPress plugin allows unauthorized actors to access sensitive information due to improper access cont...

Aug 13, 2024
CVE-2024-38742
5.3

This vulnerability in the MBE eShip WordPress plugin allows unauthorized users to access sensitive information due to improper access control restrict...

Aug 13, 2024
CVE-2024-37924
5.3

This vulnerability in the WP2Speed Faster WordPress plugin allows unauthorized actors to access sensitive information due to improper access control r...

Aug 12, 2024
CVE-2024-7413
5.3

The Obfuscate Email WordPress plugin discloses the full server path to unauthenticated attackers in all versions up to 3.8.1. This occurs because the ...

Aug 12, 2024
CVE-2024-7416
5.3

The Reveal Template WordPress plugin up to version 3.7 allows unauthenticated attackers to retrieve the full web server path via direct access to boot...

Aug 12, 2024
CVE-2024-7410
5.3

The My Custom CSS PHP & ADS WordPress plugin discloses the full server path to unauthenticated attackers through direct access to a specific file. Thi...

Aug 12, 2024
CVE-2024-6562
5.3

This vulnerability in the WordPress Affiliate Toolkit plugin allows unauthenticated attackers to obtain the full server path through path disclosure. ...

Aug 12, 2024
CVE-2024-42493
5.3

Dorsett Controls InfoScan leaks potentially sensitive information through response headers and JavaScript before user authentication. This allows atta...

Aug 8, 2024
CVE-2024-7339
5.3

This vulnerability allows remote attackers to access sensitive device information via the /queryDevInfo endpoint on affected DVR systems. It affects T...

Aug 1, 2024
CVE-2024-41694
5.3

This vulnerability in Cybonet products exposes sensitive information to unauthorized actors. It affects systems running vulnerable versions of Cybonet...

Jul 30, 2024
CVE-2024-7156
5.3

This vulnerability in TOTOLINK A3700R routers allows remote attackers to access sensitive configuration information through the ExportSettings.sh CGI ...

Jul 28, 2024
CVE-2024-5614
5.3

The Piotnet Addons For Elementor WordPress plugin exposes sensitive post data through an unauthenticated API endpoint. Unauthenticated attackers can r...

Jul 27, 2024
CVE-2024-6573
5.3

The Intelligence WordPress plugin up to version 1.4.0 allows unauthenticated attackers to retrieve the full server path via direct access to a PHP fil...

Jul 27, 2024
CVE-2024-6547
5.3

The Add Admin CSS WordPress plugin discloses full server path information to unauthenticated attackers in versions up to 2.0.1. This occurs because te...

Jul 27, 2024
CVE-2024-6549
5.3

The Admin Post Navigation WordPress plugin discloses full server path information to unauthenticated users due to test files with display_errors enabl...

Jul 27, 2024
CVE-2024-6545
5.3

The Admin Trim Interface WordPress plugin (versions up to 3.5.1) exposes full web server path information to unauthenticated attackers through test fi...

Jul 27, 2024
CVE-2024-7128
5.3

CVE-2024-7128 is an authentication bypass vulnerability in OpenShift console where endpoints using authHandler() and authHandlerWithUser() middleware ...

Jul 26, 2024
CVE-2024-6553
5.3

The WP Meteor Website Speed Optimization Addon plugin for WordPress versions up to 3.4.3 contains a full path disclosure vulnerability. Unauthenticate...

Jul 24, 2024
CVE-2024-6560
5.3

The Addonify Quick View for WooCommerce WordPress plugin discloses full server path information to unauthenticated attackers due to improper access re...

Jul 20, 2024
CVE-2024-20396
5.3

A vulnerability in Cisco Webex App's protocol handlers could allow remote attackers to capture sensitive information like credentials by tricking user...

Jul 17, 2024
CVE-2024-6336
5.3

A security misconfiguration in GitHub Enterprise Server allowed unauthorized users to access sensitive information when an organization member changed...

Jul 16, 2024
CVE-2024-27090
5.3

This vulnerability in Decidim allows attackers to access unpublished or private resources by guessing their URLs or slugs. It affects Decidim instance...

Jul 10, 2024
CVE-2024-6646
5.3

This vulnerability in Netgear WN604 wireless access points allows remote attackers to access sensitive configuration files through the /downloadFile.p...

Jul 10, 2024
CVE-2024-37498
5.3

The Tablesome WordPress plugin versions up to 1.0.33 expose sensitive data through its API endpoints without proper authorization. This allows unauthe...

Jul 10, 2024
CVE-2024-5059
5.3

This vulnerability in the WordPress Event Monster plugin (Event Management Tickets Booking) allows unauthorized actors to access sensitive information...

Jun 21, 2024
CVE-2024-35710
5.3

The Podlove Web Player WordPress plugin versions up to 5.7.3 contain a sensitive data exposure vulnerability that allows unauthorized actors to access...

Jun 8, 2024
CVE-2023-49774
5.3

This vulnerability in WP Photo Album Plus WordPress plugin allows unauthorized actors to bypass IP-based access controls, exposing sensitive informati...

Jun 4, 2024
CVE-2024-32131
5.3

This vulnerability in the WordPress Download Manager plugin allows attackers to bypass password protection on files, exposing sensitive information to...

May 17, 2024

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,079 CVEs classified as CWE-200, with 96 rated critical and 398 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.6.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free