CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,079
Total CVEs
96
Critical
398
High
6.6
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
133
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 26
5 Oracle 20
6 Google 15
7 Debian 12
8 Mozilla 10
9 Netgear 9
10 Splunk 9

All Information Exposure CVEs (1,079)

CVE-2025-13758
3.5

Devolutions Server versions through 2025.2.20 and 2025.3.8 expose credentials in unintended requests, potentially leaking sensitive authentication dat...

Nov 27, 2025
CVE-2025-20379
3.5

This vulnerability allows low-privileged Splunk users to bypass SPL safeguards for risky commands by exploiting character encoding in REST API paths. ...

Nov 12, 2025
CVE-2026-20681
3.3

This macOS vulnerability allows applications to access sensitive contact information that should be redacted in system logs. It affects macOS users ru...

Feb 11, 2026
CVE-2026-20730
3.3

A vulnerability in BIG-IP Edge Client and browser VPN clients on Windows may allow attackers to access sensitive information. This affects Windows use...

Feb 4, 2026
CVE-2025-24090
3.3

This CVE describes an information disclosure vulnerability in iOS/iPadOS where malicious apps could enumerate which other apps are installed on a devi...

Jan 16, 2026
CVE-2025-46279
3.3

This CVE describes an information disclosure vulnerability in Apple operating systems where an app could identify what other apps a user has installed...

Dec 17, 2025
CVE-2025-43437
3.3

This CVE describes an information disclosure vulnerability in iOS/iPadOS that allows apps to fingerprint users, potentially revealing unique device or...

Dec 12, 2025
CVE-2026-1197
3.1

This vulnerability in MineAdmin 1.x/2.x allows remote attackers to disclose sensitive information by manipulating the ID parameter in the /system/down...

Jan 20, 2026
CVE-2026-1196
3.1

This vulnerability in MineAdmin 1.x/2.x allows remote attackers to access sensitive information through manipulation of the ID parameter in the /syste...

Jan 20, 2026
CVE-2025-15141
3.1

This vulnerability in Halo's Configuration Handler component allows remote attackers to access sensitive information through the /actuator endpoint. I...

Dec 28, 2025
CVE-2026-26964
2.7

Windmill versions 1.634.6 and below expose Slack OAuth client secrets to non-admin users through the GET /api/w/{workspace}/workspaces/get_settings en...

Feb 20, 2026
CVE-2025-46676
2.7

Dell PowerProtect Data Domain systems running affected DD OS versions contain an information disclosure vulnerability. A high-privileged attacker with...

Jan 9, 2026
CVE-2025-15121
2.4

This vulnerability in JeecgBoot allows attackers to exploit the getDeptRoleByUserId function by manipulating the departId parameter, leading to unauth...

Dec 28, 2025
CVE-2025-31964
2.2

This vulnerability in HCL BigFix IVR 4.2 allows privileged attackers to disrupt service availability by exploiting administrative services bound to ex...

Jan 7, 2026
CVE-2026-27467
2.0

BigBlueButton versions 3.0.19 and below have a vulnerability where clients send audio to the server even when muted during initial session join. While...

Feb 21, 2026
CVE-2026-1407
2.0

This vulnerability in Beetel 777VR1 routers allows attackers with physical access to the device to extract sensitive information via the UART interfac...

Jan 25, 2026
CVE-2026-2832
N/A

Samsung MultiXpress multifunction printers expose sensitive configuration data including address book entries through unauthenticated APIs. This affec...

Feb 20, 2026
CVE-2026-1727
N/A

This vulnerability allows attackers to access sensitive information by predicting Google Cloud Storage bucket names used by the Agentspace service for...

Feb 6, 2026
CVE-2025-61639
N/A

This CVE describes an information disclosure vulnerability in MediaWiki where sensitive information can be exposed to unauthorized users. The vulnerab...

Feb 3, 2026
CVE-2025-6593
N/A

This CVE describes an information disclosure vulnerability in MediaWiki's User.php file that could allow attackers to access sensitive user data. The ...

Feb 2, 2026
CVE-2025-12738
N/A

Neo4j Enterprise edition is vulnerable to an information disclosure attack where authenticated users can infer property values they shouldn't have acc...

Jan 22, 2026
CVE-2025-14553
N/A

The TP-Link Tapo mobile app for iOS and Android exposes password hashes through an unauthenticated API response, allowing attackers on the same local ...

Dec 16, 2025
CVE-2024-38798
N/A

This CVE describes an information disclosure vulnerability in EDK2 BIOS firmware where an attacker with local access can potentially read sensitive in...

Dec 9, 2025
CVE-2025-10285
N/A

The Silicon Labs Simplicity Device Manager web interface exposes NTLMv2 authentication hashes to unauthenticated attackers when accessed publicly. Thi...

Dec 4, 2025
CVE-2025-65957
N/A

This vulnerability in Core Bot, an open-source Discord bot for Maple Hospital servers, allows sensitive API keys (SUPABASE_API_KEY, TOKEN) to be inadv...

Nov 26, 2025
CVE-2025-13596
N/A

ATISoluciones CIGES Application versions 2.15.6 and earlier expose sensitive information through detailed error messages when unhandled exceptions occ...

Nov 24, 2025
CVE-2025-12149
N/A

This vulnerability in Search Guard FLX allows unauthorized document access when searches are triggered from Signals watches. Document-Level Security (...

Nov 14, 2025
CVE-2025-11697
N/A

This vulnerability allows any Windows user on a system with Studio 5000 Simulation Interface to execute arbitrary code with Administrator privileges v...

Nov 11, 2025
CVE-2025-40645
N/A

This vulnerability allows unauthenticated attackers to retrieve sensitive customer information from Viday systems by making HTTP GET requests to a spe...

Oct 2, 2025

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,079 CVEs classified as CWE-200, with 96 rated critical and 398 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.6.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free