CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,079)
This vulnerability allows unauthenticated attackers to access restricted functionality in Progress Telerik Report Server due to a trust boundary viola...
May 15, 2024This vulnerability in TYPO3's ShowImageController allows attackers to trigger unlimited thumbnail generation by manipulating the 'frame' parameter wit...
May 14, 2024A vulnerability in RUGGEDCOM CROSSBOW allows log messages to be forwarded to a specific client under certain circumstances. Attackers could exploit th...
May 14, 2024This vulnerability in Academy LMS WordPress plugin exposes sensitive information to unauthorized actors. It affects Academy LMS versions up to 1.9.25,...
May 14, 2024This vulnerability in the Filebird WordPress plugin allows unauthorized actors to access sensitive information. It affects all Filebird installations ...
May 14, 2024This vulnerability exposes sensitive information to unauthorized actors in the RadiusTheme ShopBuilder WordPress plugin. It affects WordPress sites us...
May 14, 2024MantisBT versions before 2.26.2 have an information disclosure vulnerability where users can see metadata about notes they shouldn't have access to. W...
May 14, 2024Zitadel identity management system versions before patched releases could expose database connection details (database name, username, hostname) to us...
May 1, 2024CVE-2022-1911 is an information disclosure vulnerability in M-Files Server where an error in the parser function allows unauthenticated attackers to a...
Nov 30, 2022A permission control vulnerability in Huawei's Notepad module could allow unauthorized access to sensitive information. This affects Huawei consumer d...
Jan 14, 2026A permission control vulnerability in Huawei's Notepad module could allow unauthorized access to sensitive information. This affects Huawei device use...
Nov 28, 2025This vulnerability allows unauthorized access to Bluetooth adapter details on affected Android devices through a permissions bypass. It enables local ...
May 27, 2025EnzoH contains an OS command injection vulnerability (CWE-200) that could allow authenticated attackers to execute arbitrary commands on affected syst...
Aug 8, 2025Apache Commons VFS versions before 2.10.0 can leak FTP passwords in error messages when file operations fail. This occurs because the FtpFileObject cl...
Mar 23, 2025CVE-2024-39600 is a memory disclosure vulnerability in SAP GUI for Windows where passwords remain in memory after login, potentially allowing attacker...
Jul 9, 2024This vulnerability allows authenticated users to inject HTML content that gets rendered in other users' browsers in M-Files Web, potentially enabling ...
Mar 6, 2023This vulnerability in Umbraco CMS allows attackers with backoffice access to enumerate arbitrary files on the server filesystem by exploiting predicta...
Dec 9, 2025A vulnerability in SIMATIC CN 4100 industrial communication devices allows attackers to exploit inconsistent SNMP behavior to access sensitive data, p...
Dec 9, 2025This CVE describes an app lock verification bypass vulnerability in a file management application. Attackers could potentially access protected files ...
Dec 8, 2025This CVE describes a permission control vulnerability in Huawei's file management module that could allow unauthorized access to sensitive files. Succ...
Nov 28, 2025This vulnerability allows system administrators to access password hashes and MFA secrets through an API endpoint that fails to properly sanitize user...
Nov 14, 2025This vulnerability allows high-privileged attackers with network access via HTTP to access sensitive data in Oracle Financial Services Revenue Managem...
Oct 21, 2025An information disclosure vulnerability in SeaCMS 13.1 allows authenticated administrators to scan and download files from the server's root directory...
Oct 3, 2025This vulnerability allows Harbor administrators to exploit an ORM leak in the /api/v2.0/users endpoint to extract users' password hashes and salts cha...
Jul 25, 2025A vulnerability in OXID eShop allows CMS pages with Smarty syntax errors to display user information. This affects OXID eShop installations using CMS ...
May 13, 2025Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 may log plaintext passwords for local native authentication users when the AdminManager log c...
Oct 14, 2024The Bare Metal Operator (BMO) in Metal3 allows users with BareMetalHost creation/edit permissions to exfiltrate Kubernetes Secrets from any namespace ...
Sep 3, 2024This vulnerability allows privileged users within Zoom Workplace environments to access sensitive information through network connections. It affects ...
Aug 14, 2024vaeThink 1.0.2 contains an information disclosure vulnerability in the system backend's access management administrator function. This allows attacker...
Jul 9, 2024This vulnerability in Directus allows users with permission to view collections containing redacted hashed fields to bypass redaction and access the p...
May 14, 2024Nebari versions through 2024.4.1 expose the temporary Keycloak root password in deployment logs. This information disclosure vulnerability allows atta...
May 6, 2024A permission control vulnerability in Huawei's Notepad module could allow unauthorized access to sensitive information. This affects users of Huawei c...
Jan 14, 2026The ShareThis Dashboard for Google Analytics WordPress plugin exposes Google Analytics client credentials in plaintext within publicly accessible sour...
Jan 7, 2026BBOT's GitLab module can leak GitLab API keys to attacker-controlled servers through maliciously formatted git URLs. This affects organizations using ...
Oct 9, 2025This vulnerability allows unauthenticated attackers to access Sync account data including credentials and email protection information. It affects use...
Oct 8, 2025Rancher Manager's /meta/proxy endpoint improperly forwards Impersonate-Extra-* headers to external entities like amazonaws.com, potentially leaking se...
Oct 2, 2025This vulnerability allows malicious Domain Admins or Resource Admins in Apache CloudStack to bypass domain isolation by exploiting flawed access contr...
Jun 11, 2025This vulnerability in Intel Tiber Edge Platform's Edge Orchestrator software allows authenticated users with local access to potentially expose sensit...
May 13, 2025This CVE describes a privacy vulnerability in iOS/iPadOS where an attacker with physical access to a locked device could view sensitive user informati...
Feb 11, 2026This macOS vulnerability allows an attacker with physical access to a locked device to bypass authorization controls and view sensitive user informati...
Feb 11, 2026This vulnerability allows a physically proximate attacker to extract sensitive information from the AIRTH SMART HOME AQI MONITOR via its exposed UART ...
Jan 14, 2026This vulnerability in Nextcloud Server exposes fixed credentials for external storage configurations through the API and frontend. An attacker with an...
Nov 15, 2024This vulnerability in Nextcloud Server exposes global credentials in plain text through the API response when an attacker has access to an active user...
Nov 15, 2024Jellyfin's user profile image upload accepts SVG files that can contain malicious JavaScript. When an admin user views such an image outside the Jelly...
Sep 2, 2024EnzoH contains an OS command injection vulnerability that allows attackers to execute arbitrary commands on affected systems. This affects systems run...
Aug 8, 2025This vulnerability in Directus logs sensitive authentication tokens when using WebHook triggers in Flows, exposing access and refresh tokens in system...
Jul 15, 2025GeoServer versions 2.10.0 through 2.24.3 and 2.25.0 expose environment variables and Java properties containing sensitive credentials to authenticated...
Jul 1, 2024A permission control vulnerability in Huawei's media library module could allow unauthorized access to sensitive media files. This affects Huawei devi...
Dec 8, 2025This vulnerability allows authenticated local attackers with administrative SSH access to access sensitive information on Cisco Video Phone 8875 and C...
Feb 19, 2025This vulnerability allows group members with Developer or higher roles to access project-level analytics settings that should be restricted. It affect...
Jul 24, 2024About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,079 CVEs classified as CWE-200, with 96 rated critical and 398 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.6.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free