CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,059)
This vulnerability in the Ninja Forms WordPress plugin allows low-privileged users (like subscribers) to install and activate the SendWP plugin withou...
Apr 5, 2021This vulnerability in the Entropy Derby betting engine allows bettors to bypass the time-delay encryption system by pre-computing VDF outputs. The bet...
Nov 25, 2025This vulnerability in z80pack's GitHub Actions workflow exposes the repository's GITHUB_TOKEN in publicly accessible build artifacts. Attackers who do...
Apr 18, 2025The MoneySpace WordPress plugin exposes full payment card details including CVV codes to unauthenticated attackers. Any WordPress site using MoneySpac...
Jan 7, 2026This vulnerability in Oracle Financial Services Analytical Applications Infrastructure allows unauthenticated attackers with network access via HTTP t...
Oct 21, 2025Omni, a Kubernetes management platform, has an API vulnerability that can leak sensitive information. This affects all deployments using Omni versions...
Oct 13, 2025This vulnerability allows DNS requests to bypass SOCKS proxy configurations when Multi-Account Containers is enabled and either the domain name is inv...
Jun 24, 2025This vulnerability in Directus exposes sensitive data including environmental variables, API keys, and user information when a Flow with a Webhook tri...
Mar 26, 2025This CVE describes an information exposure vulnerability in Schneider Electric products where unauthorized actors can access restricted web pages, mod...
Jan 17, 2025The TeploBot WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to retrieve the Telegram Bot Token. This...
Oct 22, 2024An unauthenticated attacker can exploit this vulnerability in Oracle Retail Xstore Office via HTTP to access sensitive data. This affects versions 19....
Jul 16, 2024CVE-2021-23855 exposes user credentials through an unprotected web server resource in affected Bosch products. Attackers can retrieve weakly hashed pa...
Oct 4, 2021This vulnerability allows unauthenticated attackers to access sensitive configuration data including user credentials and device information through u...
Oct 4, 2021CVE-2021-32820 is a file disclosure vulnerability in express-handlebars where the layout parameter can be manipulated to read arbitrary files with exi...
May 14, 2021This vulnerability in Weave GitOps Terraform Controller allows authenticated remote attackers to view sensitive information like configurations and to...
Jul 14, 2023This vulnerability allows attackers to exploit JavaScript pre-processing in Zabbix Server or Proxy to gain read-only file system access under the 'zab...
Jul 13, 2023This vulnerability in SAP BusinessObjects Business Intelligence platform allows authenticated attackers to access sensitive information that should be...
Feb 14, 2023The Intelbras IWR 3000N router firmware version 1.9.8 exposes Wi-Fi passwords in plaintext through an unauthenticated API endpoint. Any attacker on th...
Sep 10, 2025CVE-2017-18306 is an information disclosure vulnerability in Qualcomm components that allows attackers to read uninitialized memory due to improper va...
Nov 26, 2024This vulnerability allows a network-adjacent attacker with root access to a Test Agent Appliance to access sensitive information about downstream devi...
Apr 12, 2024CVE-2023-4164 is an information disclosure vulnerability in Pixel Watch health data components where missing permission checks allow unauthorized acce...
Jan 2, 2024This CVE describes a misconfiguration in Tauri applications using Vite that can leak private signing keys and passwords into bundled frontend code. At...
Oct 20, 2023CVE-2025-26604 is a critical vulnerability in Discord-Bot-Framework-Kernel that allows arbitrary code execution through user-submitted modules, potent...
Feb 18, 2025Contao CMS versions 4.9.0 through 4.13.39 and 5.0.0 through 5.3.3 inadvertently send session cookies to external URLs when checking for broken links o...
Apr 9, 2024This vulnerability in the Responsive Menu WordPress plugin allows attackers to leak nonce tokens, which can then be used to perform unauthorized actio...
Mar 18, 2022CVE-2021-36198 is an information disclosure vulnerability in Johnson Controls Metasys products that allows unauthorized users to access sensitive data...
Dec 6, 2021This vulnerability in Azure Functions allows unauthorized access to sensitive information such as environment variables, configuration files, or appli...
Feb 5, 2026This vulnerability in Beyaz Bilgisayar CityPLus software allows unauthorized actors to detect unpublicized web pages, exposing sensitive system inform...
Oct 21, 2025Autocaliweb versions before 0.8.3 expose sensitive configuration data including API keys in debug packs. The to_dict() method fails to filter sensitiv...
Aug 12, 2025The umatiGateway software exposes its web interface publicly by default in Docker deployments, allowing unauthorized users to view and modify configur...
Mar 10, 2025This vulnerability allows attackers with valid certificates to craft malicious DDS Participants or ROS 2 Nodes that can compromise secure DDS databus ...
Jan 9, 2025This vulnerability allows attackers with valid certificates to create malicious DDS Participants or ROS 2 Nodes that can compromise and gain full cont...
Jan 9, 2025This vulnerability allows attackers with valid certificates to craft malicious DDS Participants or ROS 2 Nodes that can compromise secure DDS databus ...
Jan 9, 2025This vulnerability in Nextcloud Mail allows email account setup details to be sent to attacker-controlled servers when auto-configuration fails. Attac...
Nov 15, 2024CVE-2024-6506 is an information exposure vulnerability in the MRW plugin version 5.4.3 that allows remote attackers to access other customers' order i...
Jul 4, 2024This vulnerability in Section Camera software allows unauthorized attackers to change administrator and user account passwords without proper authenti...
May 6, 2024This vulnerability affects Brocade SANnav management software versions before v2.3.1 and v2.3.0a. It allows unauthenticated remote attackers to detect...
Apr 19, 2024This vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management allows unauthenticated attackers with network access via HTTP to acc...
Apr 16, 2024CVE-2023-39736 is an information disclosure vulnerability in Fukunaga_memberscard Line 13.6.1 that leaks client secrets, allowing attackers to obtain ...
Oct 25, 2023This vulnerability in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the client secret, which can then be used to steal the channel acces...
Oct 25, 2023An unauthenticated information exposure vulnerability in IBERMATICA RPS 2019 allows attackers to access sensitive data by triggering logging through a...
Oct 3, 2023CVE-2022-47554 allows unauthenticated remote attackers to access sensitive XML files containing credentials and other critical information in ekorCCP ...
Sep 19, 2023Parse Server LiveQuery improperly exposes protected fields to clients, allowing unauthorized access to sensitive data. This affects all Parse Server d...
Jun 30, 2022This vulnerability in Delta Electronics DVP-12SE11T PLC allows attackers to bypass authentication by obtaining partial password information through im...
Dec 30, 2025This vulnerability allows apps to bypass entitlement checks and fingerprint users on Apple devices. It affects visionOS, tvOS, iOS, iPadOS, and watchO...
Nov 4, 2025This vulnerability in Oracle Product Hub allows authenticated attackers with low privileges to perform unauthorized data manipulation and access via H...
Oct 21, 2025The Harmony SASE agent may expose sensitive log files uploaded during troubleshooting to unauthorized parties. This information disclosure vulnerabili...
Aug 12, 2025A vulnerability in Aver PTC310UV2 firmware allows remote attackers to retrieve sensitive information through specially crafted requests. This affects ...
Jul 30, 2025This vulnerability allows search terms to persist in the URL bar after navigating away from search pages, potentially exposing sensitive search querie...
Jul 22, 2025This vulnerability in Apache CloudStack allows project members with access to CKS-based Kubernetes clusters to steal the API and secret keys of the cl...
Jun 10, 2025About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,059 CVEs classified as CWE-200, with 91 rated critical and 384 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free