CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,058
Total CVEs
91
Critical
384
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
131
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,058)

CVE-2023-43791
9.8

CVE-2023-43791 is a privilege escalation vulnerability in Label Studio that allows attackers to chain an ORM leak vulnerability with other flaws to im...

Nov 9, 2023
CVE-2023-38547
9.8

This vulnerability in Veeam ONE allows unauthenticated attackers to obtain SQL server connection details for the configuration database. This informat...

Nov 7, 2023
CVE-2023-5642
9.8

This vulnerability allows unauthenticated remote attackers to read and write to the snmpmon.ini configuration file in Advantech R-SeeNet software. Att...

Oct 18, 2023
CVE-2022-48510
9.8

CVE-2022-48510 is an input verification vulnerability in Huawei's AMS (Activity Manager Service) module that allows attackers to perform unauthorized ...

Jul 6, 2023
CVE-2023-22577
9.8

CVE-2023-22577 is an information disclosure vulnerability in White Rabbit Switch that allows unauthenticated attackers to retrieve sensitive informati...

Apr 24, 2023
CVE-2023-28765
9.8

This vulnerability in SAP BusinessObjects Business Intelligence Platform allows attackers with basic privileges to access and decrypt lcmbiar files, e...

Apr 11, 2023
CVE-2023-24838
9.8

HGiga PowerStation has an information leakage vulnerability that allows unauthenticated remote attackers to obtain administrator credentials. These cr...

Mar 27, 2023
CVE-2022-32221
9.8

This vulnerability in libcurl allows an attacker to cause memory corruption or data leakage when reusing a handle from a PUT to a POST request. Applic...

Dec 5, 2022
CVE-2022-26869
9.8

Dell PowerStore storage systems have an open port vulnerability that allows remote unauthenticated attackers to access sensitive information and execu...

Jun 2, 2022
CVE-2021-3773
9.8

A netfilter flaw allows network-connected attackers to infer OpenVPN connection endpoint information by analyzing network traffic patterns. This affec...

Feb 16, 2022
CVE-2021-41301
9.8

The ECOA BAS controller has an insecure direct object reference vulnerability that allows unauthenticated attackers to access configuration files via ...

Sep 30, 2021
CVE-2021-21564
9.8

Dell OpenManage Enterprise versions before 3.6.1 have an improper authentication vulnerability that allows remote unauthenticated attackers to hijack ...

Aug 9, 2021
CVE-2021-27850
9.8

CVE-2021-27850 is a critical unauthenticated remote code execution vulnerability in Apache Tapestry that allows attackers to bypass previous security ...

Apr 15, 2021
CVE-2019-14480
9.8

CVE-2019-14480 is an improper session handling vulnerability in AdRem NetCrunch's web client that allows attackers to bypass authentication or escalat...

Dec 16, 2020
CVE-2025-59434
9.6

An authenticated vulnerability in Flowise Cloud allowed free-tier users to access sensitive environment variables from other tenants via the Custom Ja...

Sep 22, 2025
CVE-2023-50253
9.6

This vulnerability in Laf cloud development platform allows authenticated users to access logs from any Kubernetes pod within the same namespace witho...

Jan 3, 2024
CVE-2021-45652
9.6

This vulnerability in NETGEAR Orbi WiFi systems allows unauthorized disclosure of sensitive information from affected devices. It impacts NETGEAR RBK3...

Dec 26, 2021
CVE-2021-45654
9.6

NETGEAR XR1000 routers running firmware versions before 1.0.0.58 contain a vulnerability that allows unauthorized disclosure of sensitive information....

Dec 26, 2021
CVE-2025-61777
9.4

Flag Forge CTF platform versions 2.0.0 through 2.3.1 have unauthenticated API endpoints that allow unauthorized users to view all badge templates with...

Oct 6, 2025
CVE-2021-29483
9.4

CVE-2021-29483 is an information disclosure vulnerability in ManageWiki, a MediaWiki extension. It allows any user to access private configuration var...

Apr 28, 2021
CVE-2024-34711
9.3

This vulnerability in GeoServer allows unauthorized attackers to perform XML External Entity (XXE) attacks by bypassing URI validation. Attackers can ...

Jun 10, 2025
CVE-2020-7819
9.3

CVE-2020-7819 is a critical SQL injection vulnerability in nTracker USB Enterprise software that allows remote unauthenticated attackers to execute ar...

Sep 7, 2021
CVE-2025-11717
9.1

This vulnerability in Firefox for Android allows attackers to view password-related screens when switching between apps using the card carousel. Previ...

Oct 14, 2025
CVE-2024-39335
9.1

This vulnerability allows institution administrators in Mahara to view sensitive information on the 'Current submissions' page that they should not ha...

Aug 26, 2025
CVE-2025-52467
9.1

This vulnerability in the pgai Python library allowed attackers to exfiltrate all secrets used in a workflow, including the GITHUB_TOKEN with write pe...

Jun 19, 2025
CVE-2025-5098
9.1

The PrinterShare Android application allows attackers to capture Gmail authentication tokens, enabling unauthorized access to users' Gmail accounts. T...

May 23, 2025
CVE-2024-41259
9.1

CVE-2024-41259 is a vulnerability in Navidrome v0.52.3 where Gravatar's service uses an insecure hashing algorithm, allowing attackers to manipulate u...

Aug 1, 2024
CVE-2024-42049
9.1

TightVNC Server for Windows before version 2.8.84 exposes its control pipe to network connections, allowing attackers to potentially execute unauthori...

Jul 28, 2024
CVE-2024-1643
9.1

This vulnerability allows attackers to join any organization by knowing its ID, bypassing permission checks. Once joined, they gain full read/write ac...

Apr 10, 2024
CVE-2023-40275
9.1

This vulnerability in OpenClinic GA allows unauthenticated attackers to retrieve patient lists via direct API queries to searchByAjax/patientslistShow...

Mar 19, 2024
CVE-2024-27905
9.1

This vulnerability in Apache Aurora allows unauthenticated attackers to exploit an information disclosure endpoint as a padding oracle to forge valid ...

Feb 27, 2024
CVE-2024-24825
9.1

CVE-2024-24825 is an information exposure vulnerability in DIRAC distributed resource framework where any user can obtain tokens requested by other us...

Feb 9, 2024
CVE-2023-52101
9.1

This CVE describes a component exposure vulnerability in Huawei Wi-Fi modules that could allow attackers to compromise service availability and integr...

Jan 16, 2024
CVE-2023-3455
9.1

This CVE describes a key management vulnerability in Huawei systems that could allow attackers to compromise service availability and integrity. It af...

Jul 5, 2023
CVE-2023-28762
9.1

This vulnerability in SAP BusinessObjects Business Intelligence Platform allows authenticated administrators to steal login tokens of any logged-in us...

May 9, 2023
CVE-2022-48348
9.1

This vulnerability in Huawei's MediaProvider module allows unauthorized data reading, potentially exposing sensitive media files and metadata. It affe...

Mar 27, 2023
CVE-2021-45650
9.1

This vulnerability in certain NETGEAR routers allows unauthorized disclosure of sensitive information. Attackers can potentially access confidential d...

Dec 26, 2021
CVE-2020-28199
9.1

The Amazon Pay Plugin for Shopware before version 9.4.2 exposes sensitive Amazon secret keys in publicly accessible JavaScript files. This allows unau...

Feb 26, 2021
CVE-2025-59469
9.0

This vulnerability allows users with Backup Operator or Tape Operator privileges to write files with root/system-level permissions, potentially leadin...

Jan 8, 2026
CVE-2025-63729
9.0

This vulnerability allows attackers to extract SSL/TLS private keys and certificates from Syrotech GPON devices. Attackers can impersonate legitimate ...

Nov 25, 2025
CVE-2024-52975
9.0

Fleet Server logs sensitive information from Fleet policies at INFO and ERROR log levels, potentially exposing credentials, API keys, or other confide...

Jan 23, 2025
CVE-2023-48225
8.9

This vulnerability in Laf cloud development platform allows attackers to read sensitive information from Kubernetes secrets and configmaps through imp...

Dec 12, 2023
CVE-2025-7654
8.8

This vulnerability in FunnelKit plugins allows authenticated attackers with Contributor-level access or higher to extract sensitive data including aut...

Aug 19, 2025
CVE-2024-8326
8.8

The s2Member WordPress plugin contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to extract sensitiv...

Dec 17, 2024
CVE-2024-9821
8.8

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to retrieve the Telegram Bot Token via an AJAX endpoint...

Oct 12, 2024
CVE-2024-23321
8.8

This vulnerability in Apache RocketMQ allows authenticated users or IP whitelisted actors to obtain administrator credentials through specific interfa...

Jul 22, 2024
CVE-2024-27769
8.8

CVE-2024-27769 is an information disclosure vulnerability in Unitronics Unistream Unilogic software that exposes sensitive information, potentially al...

Mar 18, 2024
CVE-2024-22022
8.8

CVE-2024-22022 allows low-privileged Veeam Recovery Orchestrator users to access the NTLM hash of the service account used by the Veeam Orchestrator S...

Feb 7, 2024
CVE-2021-22783
8.8

This vulnerability allows session hijacking through information exposure when the Ritto Wiser Door panel communicates with the door. Attackers could i...

Mar 9, 2022
CVE-2021-40360
8.8

This vulnerability allows authenticated attackers on affected Siemens SIMATIC PCS 7 and WinCC systems to obtain password hashes via a public API. Atta...

Feb 9, 2022

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,058 CVEs classified as CWE-200, with 91 rated critical and 384 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free