CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,064
Total CVEs
91
Critical
389
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
132
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,064)

CVE-2024-13613
7.5

The Wise Chat WordPress plugin exposes sensitive information through insecure file storage in the uploads directory. Unauthenticated attackers can acc...

May 17, 2025
CVE-2025-26864
7.5

Apache IoTDB's OpenIdAuthorizer component logs sensitive authentication information, potentially exposing credentials or tokens to unauthorized actors...

May 14, 2025
CVE-2025-32044
7.5

CVE-2025-32044 is an information disclosure vulnerability in Moodle where unauthenticated attackers can retrieve sensitive user data including names, ...

Apr 25, 2025
CVE-2025-23174
7.5

CVE-2025-23174 is an information disclosure vulnerability that allows unauthorized actors to access sensitive data. This affects systems with improper...

Apr 21, 2025
CVE-2025-28235
7.5

This vulnerability allows attackers to retrieve administrator credentials in plaintext from Soundcraft Ui Series digital mixers via the /socket.io/1/w...

Apr 18, 2025
CVE-2025-30724
7.5

An unauthenticated vulnerability in Oracle BI Publisher's XML Services allows remote attackers to access sensitive data via HTTP. This affects Oracle ...

Apr 15, 2025
CVE-2025-29805
7.5

CVE-2025-29805 is an information disclosure vulnerability in Outlook for Android that allows unauthorized attackers to access sensitive information ov...

Apr 8, 2025
CVE-2024-13604
7.5

This vulnerability allows unauthenticated attackers to access sensitive files stored in the /wp-content/uploads/kbs directory of WordPress sites using...

Apr 5, 2025
CVE-2024-13567
7.5

This vulnerability allows unauthenticated attackers to access sensitive files stored in the Awesome Support WordPress plugin's upload directory. All W...

Apr 1, 2025
CVE-2025-30214
7.5

This vulnerability in Frappe framework allows attackers to make crafted requests that disclose sensitive information, potentially leading to account t...

Mar 25, 2025
CVE-2025-2277
7.5

This vulnerability in Devolutions Server exposes SSH passwords in the web-based authentication component due to missing password masking. An authentic...

Mar 13, 2025
CVE-2025-25975
7.5

A vulnerability in parse-git-config v3.0.0 allows attackers to read sensitive information from git configuration files through improper handling in th...

Mar 12, 2025
CVE-2025-26167
7.5

CVE-2025-26167 is an arbitrary file read vulnerability in Buffalo LS520D NAS devices running firmware version 4.53. Unauthenticated attackers can expl...

Mar 6, 2025
CVE-2024-13568
7.5

The Fluent Support WordPress plugin exposes sensitive ticket attachments to unauthenticated attackers through insecure directory access. All WordPress...

Mar 1, 2025
CVE-2025-25729
7.5

This vulnerability allows attackers to extract hardcoded cleartext credentials from Bosscomm IF740 OBD2 tablets during the update or boot process. Aff...

Feb 28, 2025
CVE-2025-25333
7.5

This vulnerability in IKEA CN iOS app version 4.13.0 allows attackers to access sensitive user information by tricking users into clicking a specially...

Feb 27, 2025
CVE-2025-22973
7.5

This vulnerability in QiboSoft QiboCMS X1.0 allows remote attackers to retrieve sensitive information by exploiting the http_curl() function in the co...

Feb 20, 2025
CVE-2024-57716
7.5

CVE-2024-57716 is an information disclosure vulnerability in trenoncourt AutoQueryable v1.7.0 that allows remote attackers to access sensitive data th...

Feb 20, 2025
CVE-2024-13622
7.5

The File Uploads Addon for WooCommerce WordPress plugin exposes sensitive customer data through insecure directory permissions. Unauthenticated attack...

Feb 18, 2025
CVE-2025-25281
7.5

This vulnerability allows attackers to manipulate URLs to access sensitive network information through improper exposure of data. It affects systems r...

Feb 13, 2025
CVE-2024-13606
7.5

The JS Help Desk WordPress plugin exposes sensitive support ticket attachments to unauthenticated attackers through an insecure directory. All WordPre...

Feb 13, 2025
CVE-2024-51123
7.5

This vulnerability in Zertificon Z1 SecureMail Gateway allows remote attackers to access sensitive information through the /compose-pdf.xhtml endpoint...

Feb 12, 2025
CVE-2024-13600
7.5

This vulnerability allows unauthenticated attackers to access sensitive file attachments from WordPress support tickets stored in an insecure director...

Feb 12, 2025
CVE-2025-0525
7.5

This vulnerability in Octopus Server allows attackers to use the preview import feature to determine whether specific files exist on the target system...

Feb 11, 2025
CVE-2025-22918
7.5

Polycom RealPresence Group 500 video conferencing systems running firmware version 20 or earlier have insecure permissions that automatically load coo...

Feb 3, 2025
CVE-2025-24899
7.5

This vulnerability in reNgine allows any authenticated user (including those with low-privilege roles like Auditor) to extract sensitive information a...

Feb 3, 2025
CVE-2024-56902
EPSS 20.8% 7.5

This vulnerability in Geovision GV-ASManager web application versions v6.1.0.0 and earlier allows attackers to access account information including cl...

Feb 3, 2025
CVE-2024-34897
7.5

The Nedis SmartLife Android app v1.4.0 contains an API key disclosure vulnerability that allows attackers to extract sensitive API keys from the appli...

Feb 3, 2025
CVE-2024-48310
7.5

AutoLib Software Systems OPAC v20.10 contains hardcoded API keys in its source code, allowing attackers to access backend APIs and potentially sensiti...

Jan 28, 2025
CVE-2024-13562
7.5

The Import WP plugin for WordPress exposes sensitive data stored in the uploads directory to unauthenticated attackers. This vulnerability affects all...

Jan 25, 2025
CVE-2024-49734
7.5

This vulnerability allows a Wi-Fi access point to determine what websites a device is visiting through VPN connections by analyzing side channel infor...

Jan 21, 2025
CVE-2024-48125
7.5

This vulnerability in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials by sending specially crafted ...

Jan 15, 2025
CVE-2025-21620
7.5

Deno's fetch() redirect handling leaks Authorization headers to unintended domains when following cross-domain redirects. This allows sensitive authen...

Jan 6, 2025
CVE-2024-53991
7.5

This vulnerability allows attackers to download Discourse backup files through nginx misconfiguration when using local storage. Only Discourse instanc...

Dec 19, 2024
CVE-2024-54151
7.5

This vulnerability in Directus allows unauthenticated users to perform any CRUD operations or subscribe to data changes with full admin privileges whe...

Dec 9, 2024
CVE-2024-53862
7.5

This vulnerability in Argo Workflows allows attackers to retrieve archived workflows without proper authentication. When using client or SSO authentic...

Dec 2, 2024
CVE-2024-38647
7.5

This CVE describes an information exposure vulnerability in QNAP AI Core that could allow remote attackers to access sensitive system information. The...

Nov 22, 2024
CVE-2024-43416
7.5

This vulnerability allows unauthenticated attackers to determine whether specific email addresses correspond to valid GLPI user accounts. It affects G...

Nov 18, 2024
CVE-2024-45791
7.5

Apache HertzBeat versions before 1.6.1 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive information...

Nov 18, 2024
CVE-2024-47915
7.5

CVE-2024-47915 in VaeMendis software exposes sensitive information to unauthorized actors, allowing attackers to access confidential data without auth...

Nov 14, 2024
CVE-2024-6861
7.5

This vulnerability in Foreman's GraphQL API allows attackers to retrieve sensitive admin authentication keys when introspection is enabled. This could...

Nov 6, 2024
CVE-2024-51739
7.5

CVE-2024-51739 is an information disclosure vulnerability in Combodo iTop that allows unauthenticated attackers to enumerate valid user accounts via t...

Nov 5, 2024
CVE-2024-49357
7.5

ZimaOS versions 1.2.4 and earlier expose sensitive system and application data through unauthenticated API endpoints. Attackers can access detailed in...

Oct 24, 2024
CVE-2024-48789
7.5

A vulnerability in INATRONIC DriveDeck Home firmware update process allows remote attackers to access sensitive information. This affects users of the...

Oct 14, 2024
CVE-2024-48796
7.5

This vulnerability in EQUES com.eques.plug firmware allows remote attackers to access sensitive information during the firmware update process. Attack...

Oct 14, 2024
CVE-2024-48798
7.5

This vulnerability in Hubble Connected's Vervelife app allows remote attackers to access sensitive information through the firmware update process. At...

Oct 14, 2024
CVE-2024-46471
7.5

This vulnerability allows unauthenticated directory listing of the /uploads/ folder in CodeAstro Membership Management System 1.0, exposing file struc...

Sep 27, 2024
CVE-2024-47197
7.5

The Maven Archetype Plugin versions 3.2.1 through 3.2.x expose sensitive credentials by copying the user's settings.xml file into test artifacts. This...

Sep 26, 2024
CVE-2024-44152
7.5

This macOS vulnerability allows applications to access sensitive user data from system logs that should have been redacted. It affects macOS systems b...

Sep 17, 2024
CVE-2024-8777
7.5

OMFLOW from The SYSCOM Group has an information leakage vulnerability that allows unauthorized remote attackers to read arbitrary system configuration...

Sep 16, 2024

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,064 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free