CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,061
Total CVEs
91
Critical
386
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
132
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,061)

CVE-2023-40723
8.1

This vulnerability in Fortinet FortiSIEM allows attackers to execute unauthorized code or commands via API requests, potentially leading to full syste...

Mar 11, 2025
CVE-2024-52323
8.1

This vulnerability allows authenticated users in Zohocorp ManageEngine Analytics Plus to retrieve sensitive tokens associated with the org-admin accou...

Nov 27, 2024
CVE-2024-21152
8.1

This vulnerability in Oracle Process Manufacturing Financials allows authenticated attackers with low privileges to access and modify critical data vi...

Jul 16, 2024
CVE-2024-6426
8.1

This vulnerability in MESbook 20221021.03 allows a local attacker with user privileges to access unauthorized resources by manipulating API values. It...

Jul 3, 2024
CVE-2024-37325
8.1

This vulnerability allows authenticated users on Azure Data Science Virtual Machines (DSVM) to elevate privileges to root/administrator level. It affe...

Jun 11, 2024
CVE-2024-5133
8.1

This vulnerability allows authenticated users to capture password recovery tokens from other users via the API, enabling account takeover by resetting...

Jun 6, 2024
CVE-2024-26470
8.1

A host header injection vulnerability in FullStackHero's WebAPI Boilerplate allows attackers to leak password reset tokens by manipulating the host he...

Feb 29, 2024
CVE-2022-44589
8.1

This vulnerability in the miniOrange WordPress Two Factor Authentication plugin exposes sensitive information to unauthorized actors. It affects all v...

Dec 29, 2023
CVE-2023-47619
8.1

CVE-2023-47619 is a critical vulnerability in Audiobookshelf where users with update permissions can read arbitrary files, delete arbitrary files, and...

Dec 13, 2023
CVE-2023-40580
8.1

This vulnerability allows malicious websites to access the recovery mnemonic phrase when the Freighter Stellar wallet browser extension is unlocked. I...

Aug 25, 2023
CVE-2023-37379
8.1

This vulnerability in Apache Airflow allows authenticated users with Connection edit privileges to access connection information and abuse the test co...

Aug 23, 2023
CVE-2021-43938
8.1

CVE-2021-43938 allows unauthenticated attackers to access sensitive files on Elcomplus SmartPTT SCADA Server without credentials. This affects organiz...

Apr 29, 2022
CVE-2021-43963
8.1

CVE-2021-43963 is a privilege escalation vulnerability in Couchbase Sync Gateway where bucket credentials are insecurely stored in sync documents. Use...

Dec 7, 2021
CVE-2021-32689
8.1

This vulnerability in Nextcloud Talk allows user impersonation through username reuse, enabling unauthorized access to chat messages. Attackers who ca...

Jul 12, 2021
CVE-2021-23204
8.1

This vulnerability exposes OSDP key material to unauthorized Command Centre Operators in Gallagher Command Centre Server, potentially allowing them to...

Jun 11, 2021
CVE-2025-22961
8.0

Unauthenticated attackers can access sensitive database backup files containing user credentials through exposed URLs in GatesAir Maxiva transmitters'...

Feb 13, 2025
CVE-2025-22960
8.0

Unauthenticated attackers can access debug log files containing session IDs and authentication tokens in GatesAir Maxiva transmitters. This allows ses...

Feb 13, 2025
CVE-2024-8979
8.0

The Essential Addons for Elementor WordPress plugin exposes sensitive user information through password reset email notifications. Authenticated attac...

Nov 15, 2024
CVE-2024-21380
8.0

This vulnerability in Microsoft Dynamics Business Central/NAV allows attackers to access sensitive information without proper authorization. It affect...

Feb 13, 2024
CVE-2022-29248
8.0

Guzzle PHP HTTP client versions prior to 6.5.6 and 7.4.3 have a cookie domain validation vulnerability that allows malicious servers to set cookies fo...

May 25, 2022
CVE-2021-22825
8.0

This vulnerability allows attackers to gain elevated system privileges by tricking a privileged user into clicking a malicious URL that compromises se...

Jan 28, 2022
CVE-2021-24945
8.0

The LikeBtn WordPress plugin before version 2.6.38 lacks authorization and CSRF protection in its export function, allowing any authenticated user (ev...

Dec 13, 2021
CVE-2021-42536
8.0

CVE-2021-42536 allows unauthorized users to read sensitive global variables containing peer username and password credentials. This affects systems ru...

Oct 22, 2021
CVE-2024-37307
7.9

CVE-2024-37307 is a sensitive data exposure vulnerability in Cilium's cilium-bugtool debugging utility. When run with the --envoy-dump flag against de...

Jun 13, 2024
CVE-2021-45649
7.9

This vulnerability in certain NETGEAR routers allows unauthorized disclosure of sensitive information. Attackers can potentially access confidential d...

Dec 26, 2021
CVE-2024-3780
7.8

A local information exposure vulnerability in Technicolor CGA2121 routers allows attackers with physical or network access to extract sensitive WiFi c...

Apr 15, 2024
CVE-2021-41850
7.8

This vulnerability allows any third-party app on affected Luna Simo devices to read the device's IMEI values without requiring any permissions. The IM...

Mar 11, 2022
CVE-2022-0516
7.8

A local privilege escalation vulnerability in the KVM subsystem for s390 architecture in Linux kernel allows a local attacker with normal user privile...

Mar 10, 2022
CVE-2021-0602
7.8

This vulnerability allows guest users on Android devices to view and modify Wi-Fi settings for all configured access points due to a permissions bypas...

Jul 14, 2021
CVE-2025-61917
7.7

This vulnerability in n8n workflow automation platform allows uninitialized memory allocation via Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in...

Feb 4, 2026
CVE-2025-64324
7.7

A logic bug in KubeVirt's hostDisk feature allows attackers to read and write arbitrary files owned by privileged users on the host system. This affec...

Nov 18, 2025
CVE-2025-61679
7.7

Anyquery versions 0.4.3 and below expose an unauthenticated HTTP server on localhost that allows attackers with local access to access private integra...

Oct 3, 2025
CVE-2025-53781
7.7

This vulnerability in Azure Virtual Machines allows an authorized attacker to access sensitive information over the network. It affects Azure VM deplo...

Aug 12, 2025
CVE-2025-31207
7.7

This vulnerability allows malicious iOS/iPadOS apps to enumerate which other apps are installed on a user's device. It affects users running iOS/iPadO...

May 12, 2025
CVE-2025-23212
7.7

CVE-2025-23212 is an information disclosure vulnerability in Tandoor Recipes that allows any user to enumerate and read files on the server through th...

Jan 28, 2025
CVE-2025-24174
7.7

This CVE describes a privacy preference bypass vulnerability in macOS that allows applications to circumvent user-configured privacy settings. Affecte...

Jan 27, 2025
CVE-2024-43707
7.7

This CVE describes an information disclosure vulnerability in Kibana where users without Fleet privileges can view Elastic Agent policies that may con...

Jan 23, 2025
CVE-2024-36955
7.7

This CVE describes a memory leak vulnerability in the Linux kernel's ALSA HDA Intel SoundWire ACPI driver. The vulnerability occurs when device_get_na...

May 30, 2024
CVE-2024-1139
7.7

A credentials leak vulnerability in the OpenShift Container Platform (OCP) cluster monitoring operator allows remote attackers with basic login creden...

Apr 25, 2024
CVE-2024-28236
7.7

This vulnerability in Vela CI/CD framework allows pipeline authors to bypass secret masking by injecting secrets into plugin parameters, which can the...

Mar 12, 2024
CVE-2024-23506
7.7

The InstaWP Connect WordPress plugin versions up to 0.1.0.9 contain a sensitive data exposure vulnerability that allows unauthorized actors to access ...

Jan 27, 2024
CVE-2023-3361
7.7

This vulnerability in Red Hat OpenShift Data Science exposes S3 credentials in plain text when exporting pipelines from the Elyra notebook pipeline ed...

Oct 4, 2023
CVE-2022-31090
7.7

Guzzle PHP HTTP client versions before 6.5.8 and 7.4.5 leak Authorization headers during cross-origin redirects when using the cURL handler. This expo...

Jun 27, 2022
CVE-2025-70963
7.6

Gophish versions up to 0.12.1 expose users' long-lived API keys in the HTML/JavaScript of the administrative dashboard on every login. This allows any...

Feb 6, 2026
CVE-2025-31955
7.6

HCL iAutomate has a sensitive data exposure vulnerability that allows unauthorized access to confidential information stored within the system. This a...

Jul 24, 2025
CVE-2024-37150
7.6

Deno 1.44.0 incorrectly sends .npmrc authentication credentials to tarball URLs on different domains when a private registry provides cross-domain tar...

Jun 6, 2024
CVE-2024-4173
7.6

This vulnerability exposes Kafka services on the WAN interface of Brocade SANnav management software, allowing unauthenticated attackers to perform de...

Apr 25, 2024
CVE-2024-24757
7.6

CVE-2024-24757 is an information exposure vulnerability in open-irs where sensitive environment variables from the .env file were accidentally committ...

Feb 2, 2024
CVE-2023-30853
7.6

A vulnerability in Gradle Build Action versions prior to 2.4.2 exposes GitHub Actions secrets when the Gradle configuration cache is enabled. Secrets ...

Apr 28, 2023
CVE-2021-45493
7.6

This vulnerability allows attackers to obtain administrative credentials on affected NETGEAR routers. It affects RAX35, RAX38, and RAX40 routers runni...

Dec 26, 2021

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,061 CVEs classified as CWE-200, with 91 rated critical and 386 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free