CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,064)
This vulnerability allows attackers to obtain administrative credentials on affected NETGEAR routers. It affects RAX35, RAX38, and RAX40 routers runni...
Dec 26, 2021Scraparr versions 3.0.0-beta through 3.0.1 expose Readarr API keys in Prometheus metrics when Readarr integration is enabled without an alias. This al...
Feb 12, 2026CVE-2024-26480 is an information disclosure vulnerability in Statping-ng v0.91.0 that allows attackers to access sensitive information through crafted...
Feb 11, 2026CVE-2024-26477 is an information disclosure vulnerability in Statping-ng v0.91.0 that allows attackers to access sensitive information through crafted...
Feb 11, 2026The Ninja Forms WordPress plugin has a vulnerability that allows unauthenticated attackers to extract sensitive post metadata from any post on the sit...
Feb 10, 2026The MCP Salesforce Connector prior to version 0.1.10 allows arbitrary attribute access that can lead to disclosure of Salesforce authentication tokens...
Feb 6, 2026This vulnerability allows unauthorized access to forum post custom fields through JSON output, bypassing access control settings. It affects EasyDiscu...
Feb 6, 2026This vulnerability allows unauthorized actors to access directory listings in AKCE Software Technology's SKSPro software, potentially exposing sensiti...
Feb 3, 2026This timing attack vulnerability in PolarLearn allows unauthenticated attackers to enumerate valid user email addresses by measuring login response ti...
Feb 2, 2026This vulnerability in Discourse allows attackers to obtain sensitive information about private resources through URL redirects. When users without pro...
Jan 28, 2026This vulnerability in continuous.software aangine v.2025.2 allows remote attackers to access sensitive information through multiple service endpoints....
Jan 26, 2026An unauthenticated information disclosure vulnerability in the Aptsys gemscms backend platform exposes cashier account details including MD5-hashed pa...
Jan 23, 2026This vulnerability in ALGO 8180 IP Audio Alerter devices allows remote attackers to obtain authentication cookies from the web UI response body withou...
Jan 23, 2026This vulnerability in Apache Airflow exposes sensitive values like passwords and API keys in cleartext in the Rendered Templates UI when template fiel...
Jan 16, 2026This vulnerability allows unauthenticated attackers to retrieve plaintext passwords for all users, including administrators, via exposed APIs in BLUVO...
Jan 14, 2026A vulnerability in HPE Instant On Access Points router mode configuration exposes internal network configuration details through packet inspection. Ma...
Jan 13, 2026This vulnerability allows unauthenticated remote attackers to retrieve sensitive information from Senstar Symphony installations via the FetchStoredLi...
Dec 23, 2025This vulnerability allows unauthorized attackers to access sensitive information through insecure permissions in the GT Edge AI Platform's /api/v1/age...
Dec 22, 2025In Delphix Continuous Compliance 2025.3.0+, incorrect End-of-Record (EOR) configuration for delimited files can cause parsing errors that leave person...
Dec 20, 2025A FaceTime remote control vulnerability allows password fields to be unintentionally revealed during screen sharing sessions. This affects users of Ap...
Dec 12, 2025This CVE describes a Spectre-style speculative execution vulnerability in XiangShan RISC-V processors that allows attackers to extract sensitive infor...
Dec 10, 2025A directory traversal vulnerability in ComposioHQ v0.7.20 allows remote attackers to access sensitive files outside the intended directory via the _do...
Dec 4, 2025This vulnerability allows unauthenticated attackers to determine valid usernames in TCMAN GIM v11 systems by exploiting a user enumeration flaw in the...
Dec 2, 2025This vulnerability allows unauthenticated attackers to determine valid usernames in TCMAN GIM v11 systems by exploiting a user enumeration flaw in the...
Dec 2, 2025An unauthenticated information disclosure vulnerability in GroceryMart's users.json file exposes plaintext credentials. Attackers can access usernames...
Nov 26, 2025The OneClick Chat to Order WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to access sens...
Nov 22, 2025This vulnerability allows unauthenticated attackers to retrieve admin credentials and system settings from ELCA Star Transmitter Remote Control device...
Nov 19, 2025This vulnerability allows attackers to retrieve sensitive information including administrator passwords via the /probe/core/setup/passwd endpoint in b...
Nov 19, 2025This vulnerability allows remote unauthenticated attackers to access a web-accessible database backup file containing the complete database schema and...
Nov 14, 2025This vulnerability in Desktop Alert PingAlert exposes sensitive information to unauthorized actors. It affects users running Application Server versio...
Nov 14, 2025This vulnerability in the File Manager for Google Drive WordPress plugin exposes sensitive Google OAuth credentials and account email addresses to una...
Nov 5, 2025This vulnerability in BESSystem BES Application Server allows unauthorized attackers to access sensitive information through improper configuration of...
Oct 28, 2025This vulnerability allows unauthorized disclosure of email passwords in BLU-IC2 and BLU-IC4 devices. Attackers can potentially access sensitive email ...
Oct 27, 2025This vulnerability in CBK Soft's enVision software allows attackers to perform account footprinting by exploiting observable discrepancies that expose...
Oct 24, 2025This vulnerability in Oracle Java's JAXP component allows unauthenticated attackers to access sensitive data via network protocols. It affects multipl...
Oct 21, 2025This vulnerability in AutoBizLine's com.mysecondline.app allows attackers to bypass authentication and log in as other users, gaining unauthorized acc...
Oct 21, 2025CVE-2025-61665 is a broken access control vulnerability in WeGIA, an open-source web manager for charitable institutions. Unauthenticated attackers ca...
Oct 2, 2025YOSHOP 2.0 exposes sensitive user information through unauthenticated API endpoints. Attackers can retrieve bcrypt password hashes, mobile numbers, an...
Oct 2, 2025CVE-2025-45994 is an information disclosure vulnerability in Aranda PassRecovery v1.0 that allows attackers to enumerate valid Active Directory user a...
Sep 26, 2025This vulnerability in Firefox for Android's Privacy component allows attackers to bypass privacy protections and access sensitive information that sho...
Sep 16, 2025Hoverfly versions 1.11.3 and prior have an authentication bypass vulnerability in the admin WebSocket endpoint /api/v2/ws/logs. Unauthenticated attack...
Sep 10, 2025The Xagio SEO plugin for WordPress versions up to 7.1.0.5 exposes sensitive data through its backup functionality due to weak filename structure and l...
Aug 28, 2025Mahara's experimental HTML bulk export feature fails to clear cached images between user exports, allowing users who receive exported files to potenti...
Aug 25, 2025This vulnerability in Microsoft Exchange Server allows unauthorized attackers to access sensitive information over the network. Attackers can exploit ...
Aug 12, 2025This vulnerability in Emsisoft Anti-Malware allows remote attackers to steal Net-NTLMv2 hashes by tricking users into scanning specially crafted A2S f...
Aug 5, 2025This vulnerability in Perplexity AI GPT-4 version 2.51.0 allows attackers to extract sensitive information from shared chat URLs by exploiting the tok...
Jul 18, 2025The Total Upkeep WordPress backup plugin exposes sensitive information through publicly accessible files (env-info.php and restore-info.json), allowin...
Jul 12, 2025Discourse users on vulnerable versions can continue to view their own 'whisper' posts even after being removed from groups with whisper permissions. T...
Jun 25, 2025This vulnerability in Versa Director SD-WAN orchestration platform exposes the websockify service on port 6080 by default, allowing internet access to...
Jun 19, 2025An absolute path disclosure vulnerability in DM Corporative CMS allows attackers to view webroot file contents by accessing non-existent files. This e...
Jun 10, 2025About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,064 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free