CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,079
Total CVEs
96
Critical
398
High
6.6
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
133
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 26
5 Oracle 20
6 Google 15
7 Debian 12
8 Mozilla 10
9 Netgear 9
10 Splunk 9

All Information Exposure CVEs (1,079)

CVE-2026-26326
4.3

OpenClaw personal AI assistant versions before 2026.2.14 could expose sensitive configuration secrets to clients with read-only permissions. The vulne...

Feb 19, 2026
CVE-2026-20141
4.3

A low-privileged user without admin role can access Splunk Monitoring Console endpoints due to improper access control in vulnerable Splunk Enterprise...

Feb 18, 2026
CVE-2026-2205
4.3

This vulnerability in WeKan allows remote attackers to access sensitive information through the Meteor Publication Handler in the cards.js component. ...

Feb 8, 2026
CVE-2025-15527
4.3

The WP Recipe Maker WordPress plugin up to version 10.2.2 contains an information exposure vulnerability where authenticated users with Contributor-le...

Jan 16, 2026
CVE-2025-12512
4.3

The GenerateBlocks WordPress plugin up to version 2.1.2 has an information exposure vulnerability that allows authenticated users with Contributor-lev...

Dec 13, 2025
CVE-2025-40941
4.3

SIMATIC CN 4100 devices expose server information in responses, allowing attackers with network access to gather reconnaissance data. This information...

Dec 9, 2025
CVE-2025-12558
4.3

The Beaver Builder WordPress plugin up to version 2.9.4 contains an information disclosure vulnerability that allows authenticated users with Contribu...

Dec 9, 2025
CVE-2025-20383
4.3

This vulnerability allows low-privileged Splunk users who subscribe to mobile push notifications to receive notification titles and descriptions for r...

Dec 3, 2025
CVE-2025-13653
4.3

This vulnerability allows authenticated users in Search Guard FLX to read documents from data streams without proper authorization when enterprise mod...

Dec 1, 2025
CVE-2025-13804
4.3

This CVE describes an information disclosure vulnerability in nutzam NutzBoot's Ethereum Wallet Handler component. Attackers can remotely exploit this...

Dec 1, 2025
CVE-2025-13785
4.3

This vulnerability in yungifez Skuul School Management System allows remote attackers to access sensitive information through improper handling of ima...

Nov 30, 2025
CVE-2025-66290
4.3

This vulnerability allows any authenticated user in OrangeHRM to download candidate attachments (CVs, documents) without proper authorization checks. ...

Nov 29, 2025
CVE-2025-66291
4.3

OrangeHRM versions 5.0 to 5.7 have an authorization bypass vulnerability in the Recruitment module's interview attachment endpoint. Authenticated ESS-...

Nov 29, 2025
CVE-2025-12559
4.3

This vulnerability allows any authenticated Mattermost user to view team email addresses that should only be visible to Team Admins. The information d...

Nov 27, 2025
CVE-2025-13765
4.3

CVE-2025-13765 allows non-administrative users in Devolutions Server to access email service credentials, potentially exposing sensitive authenticatio...

Nov 27, 2025
CVE-2025-59454
4.3

This CVE describes an information disclosure vulnerability in Apache CloudStack where authorized users could occasionally access data beyond their int...

Nov 27, 2025
CVE-2025-52669
4.3

This vulnerability allows non-admin users in Revive Adserver to view contact names and email addresses of other users due to insecure design policies....

Nov 20, 2025
CVE-2025-54971
4.3

This vulnerability allows read-only administrators in Fortinet FortiADC to access external resource passwords through system logs. It affects multiple...

Nov 18, 2025
CVE-2025-64705
4.3

CVE-2025-64705 is an information disclosure vulnerability in Frappe Learning Management System (LMS) that allows authenticated users to access other s...

Nov 12, 2025
CVE-2025-12732
4.3

This vulnerability in the WP Import – Ultimate CSV XML Importer WordPress plugin allows authenticated attackers with Author-level access or higher t...

Nov 12, 2025
CVE-2025-20377
4.3

An authenticated information disclosure vulnerability in Cisco Unified Intelligence Center allows low-privileged users to access sensitive system info...

Nov 5, 2025
CVE-2025-12297
4.3

This vulnerability in atjiu pybbs allows remote attackers to access sensitive information through an unknown function in UserApiController.java. It af...

Oct 27, 2025
CVE-2025-61885
4.3

This vulnerability allows authenticated attackers with low privileges to read sensitive data from Oracle Life Sciences InForm web servers. It affects ...

Oct 21, 2025
CVE-2025-61750
4.3

This vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows authenticated attackers with low privileges to read sensitive data they shouldn'...

Oct 21, 2025
CVE-2025-61906
4.3

Opencast's editor may publish videos without user notification when users with write access click 'Save & Publish' then select 'Save' instead. This co...

Oct 8, 2025
CVE-2025-10607
4.3

This vulnerability in Portabilis i-Educar allows unauthorized access to class information via the /module/Avaliacao/diarioApi endpoint. Attackers can ...

Sep 17, 2025
CVE-2025-55052
4.3

CVE-2025-55052 is an information disclosure vulnerability that allows unauthorized actors to access sensitive data. This affects systems with the vuln...

Sep 9, 2025
CVE-2025-59019
4.3

This vulnerability allows authenticated backend users in TYPO3 CMS to download CSV files containing data from database tables they shouldn't have acce...

Sep 9, 2025
CVE-2025-58458
4.3

This vulnerability in Jenkins Git client Plugin allows attackers with Overall/Read permission to determine whether specific file paths exist on the Je...

Sep 3, 2025
CVE-2025-9774
4.3

This vulnerability in RemoteClinic allows attackers to remotely exploit the /patients/edit-patient.php endpoint by manipulating the Email parameter, l...

Sep 1, 2025
CVE-2025-9461
4.3

This CVE describes an information disclosure vulnerability in diyhi bbs versions up to 6.8. Attackers can exploit a flaw in the File Compression Handl...

Aug 26, 2025
CVE-2025-9240
4.3

CVE-2025-9240 is an information disclosure vulnerability in elunez eladmin up to version 2.7. The flaw in the /auth/info endpoint allows remote attack...

Aug 20, 2025
CVE-2025-9139
4.3

This vulnerability in Scada-LTS 2.7.8.1 allows information disclosure through the /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr endpoint. Attack...

Aug 19, 2025
CVE-2025-8091
4.3

The EventON Lite WordPress plugin versions up to 2.4.6 contain an information exposure vulnerability that allows unauthenticated attackers to access p...

Aug 15, 2025
CVE-2025-8676
4.3

The B Slider WordPress plugin exposes installed plugin information to authenticated users with subscriber-level access or higher. This vulnerability a...

Aug 15, 2025
CVE-2025-55673
4.3

This vulnerability allows guest users in Apache Superset to access database schema information through the /chart/data endpoint. The API response impr...

Aug 14, 2025
CVE-2025-8852
4.3

This vulnerability in WuKongCRM 11.0 allows remote attackers to obtain sensitive information through error messages exposed by the API Response Handle...

Aug 11, 2025
CVE-2025-46388
4.3

CVE-2025-46388 is an information disclosure vulnerability (CWE-200) that allows unauthorized actors to access sensitive information. This affects syst...

Aug 6, 2025
CVE-2025-8226
4.3

This vulnerability in ChanCMS allows remote attackers to access sensitive information by manipulating accessKey/secretKey parameters in the /sysApp/fi...

Jul 27, 2025
CVE-2025-25250
4.3

This vulnerability allows authenticated SSL-VPN users to access full SSL-VPN configuration settings through specially crafted URLs. It affects FortiOS...

Jun 10, 2025
CVE-2025-20129
4.3

An unauthenticated remote attacker can exploit improper HTTP request sanitization in Cisco Customer Collaboration Platform's web chat interface to red...

Jun 4, 2025
CVE-2025-5266
4.3

This CVE describes an XS-Leaks (Cross-Site Leaks) vulnerability in Firefox and Thunderbird where script elements loading cross-origin resources genera...

May 27, 2025
CVE-2025-5184
4.3

This vulnerability in Summer Pearl Group Vacation Rental Management Platform allows remote attackers to obtain sensitive information through improper ...

May 26, 2025
CVE-2025-4901
4.3

This vulnerability in D-Link DI-7003GV2 routers allows attackers on the local network to access sensitive information through the HTTP endpoint. The i...

May 19, 2025
CVE-2025-4526
4.3

This vulnerability in DΓ­gitro NGC Explorer 3.44.15 exposes password fields on configuration pages without proper masking, allowing shoulder surfing o...

May 11, 2025
CVE-2025-4281
4.3

This vulnerability in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7 allows remote attackers to access sensitive informatio...

May 5, 2025
CVE-2025-3966
4.3

This vulnerability in paicoding 1.0.3 allows unauthorized users to view other users' browsing history through the /user/home endpoint. Attackers can r...

Apr 27, 2025
CVE-2025-2786
4.3

This vulnerability in Tempo Operator allows users with full namespace access to extract ServiceAccount tokens and use them to query Kubernetes API per...

Apr 2, 2025
CVE-2024-10321
4.3

This vulnerability in the WidgetKit plugin for WordPress allows authenticated users with Contributor-level access or higher to view sensitive template...

Mar 8, 2025
CVE-2024-13546
4.3

The GenerateBlocks WordPress plugin exposes sensitive content from private, draft, and scheduled posts/pages through the 'get_image_description' funct...

Mar 1, 2025

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,079 CVEs classified as CWE-200, with 96 rated critical and 398 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.6.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free