CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,064
Total CVEs
91
Critical
389
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
132
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,064)

CVE-2024-46938
7.5

An unauthenticated attacker can read arbitrary files on Sitecore Experience Platform, Experience Manager, and Experience Commerce systems. This vulner...

Sep 15, 2024
CVE-2024-45624
7.5

This vulnerability in Pgpool-II allows unauthorized database users to access cached query results containing sensitive table data they shouldn't have ...

Sep 12, 2024
CVE-2024-45388
7.5

CVE-2024-45388 is a path traversal vulnerability in Hoverfly's simulation API that allows attackers to read arbitrary files from the server filesystem...

Sep 2, 2024
CVE-2024-42006
7.5

Keyfactor AWS Orchestrator through version 2.0 contains an information disclosure vulnerability that allows unauthorized access to sensitive data. Thi...

Aug 20, 2024
CVE-2024-41700
7.5

This CVE describes an information exposure vulnerability in Barix products where sensitive information is accessible to unauthorized actors. Attackers...

Aug 20, 2024
CVE-2024-27120
7.5

CVE-2024-27120 is a Local File Inclusion vulnerability in ComfortKey software from Celsius Benelux that allows unauthenticated attackers to read sensi...

Aug 14, 2024
CVE-2024-38787
7.5

This vulnerability in the WordPress 'Import and export users and customers' plugin allows unauthorized actors to access sensitive information through ...

Aug 13, 2024
CVE-2024-42010
7.5

This vulnerability in Roundcube webmail allows remote attackers to exfiltrate sensitive information from rendered email messages due to insufficient C...

Aug 5, 2024
CVE-2024-38761
7.5

The Zephyr Project Manager WordPress plugin versions up to 3.3.99 contain a vulnerability that exposes sensitive information via export files. This al...

Aug 1, 2024
CVE-2024-40554
7.5

An access control vulnerability in Tmall_demo v2024.07.03 allows attackers to bypass authentication mechanisms and access sensitive information. This ...

Jul 15, 2024
CVE-2024-37110
7.5

CVE-2024-37110 is an unauthenticated information disclosure vulnerability in the WordPress WishList Member X plugin. It allows attackers without crede...

Jul 10, 2024
CVE-2023-52237
7.5

This vulnerability in Siemens RUGGEDCOM industrial networking devices allows low-privileged authenticated users to access password hashes and salts fo...

Jul 9, 2024
CVE-2024-40597
7.5

The CheckUser extension for MediaWiki fails to respect the log_deleted attribute, allowing unauthorized users to view suppressed log information. This...

Jul 7, 2024
CVE-2024-36829
7.5

This vulnerability in Teldat M1 routers allows attackers to bypass access controls and retrieve sensitive information by manipulating query strings. I...

Jun 26, 2024
CVE-2024-30472
7.5

Dell ThinOS 2402's Telemetry Dashboard v1.0.0.8 contains a sensitive information disclosure vulnerability. An unauthenticated attacker with local acce...

Jun 13, 2024
CVE-2024-35178
7.5

CVE-2024-35178 allows unauthenticated attackers to leak NTLMv2 password hashes from Windows users running vulnerable Jupyter Server instances. This af...

Jun 6, 2024
CVE-2024-33865
7.5

This vulnerability in linqi Windows versions before 1.4.0.1 allows attackers to leak NTLM hashes through specific API endpoints. Attackers can potenti...

May 14, 2024
CVE-2024-34388
7.5

The Scribit GDPR Compliance WordPress plugin versions up to 1.2.5 contain a sensitive data exposure vulnerability that allows unauthorized actors to a...

May 6, 2024
CVE-2023-40510
7.5

This vulnerability allows remote attackers to bypass authentication on LG Simple Editor installations by exploiting a flaw in the getServerSetting met...

May 3, 2024
CVE-2024-33437
7.5

CVE-2024-33437 is a vulnerability in CSS Exfil Protection v1.1.0 that allows remote attackers to exfiltrate sensitive information due to incomplete CS...

Apr 30, 2024
CVE-2024-33309
7.5

This vulnerability in TVS Connect mobile apps allows remote attackers to access sensitive information through an insecure API endpoint. It affects And...

Apr 30, 2024
CVE-2024-32816
7.5

This vulnerability in the PickPlugins Post Grid WordPress plugin exposes sensitive information through an API endpoint to unauthorized actors. It affe...

Apr 24, 2024
CVE-2024-32781
7.5

This vulnerability in ThemeHigh's Email Customizer for WooCommerce WordPress plugin exposes sensitive information to unauthorized actors. It affects a...

Apr 24, 2024
CVE-2024-32726
7.5

This CVE describes a sensitive data exposure vulnerability in the WordPress Frontend Dashboard plugin by vinoth06. The vulnerability allows unauthoriz...

Apr 24, 2024
CVE-2024-21073
7.5

This vulnerability in Oracle Trade Management allows unauthenticated attackers to access sensitive data via HTTP. It affects Oracle E-Business Suite v...

Apr 16, 2024
CVE-2024-21077
7.5

This vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Trade Management, potentially gaining unauthoriz...

Apr 16, 2024
CVE-2024-32086
7.5

This vulnerability allows unauthenticated attackers to access sensitive user and post data in the Citadela Listing WordPress plugin. It affects all Wo...

Apr 16, 2024
CVE-2024-29843
7.5

The Evolution Controller web interface contains an access control vulnerability in the MOBILE_GET_USERS_LIST endpoint that allows unauthenticated atta...

Apr 15, 2024
CVE-2024-29839
7.5

The Evolution Controller web interface has an access control vulnerability in the DESKTOP_EDIT_USER_GET_CARD endpoint that allows unauthenticated atta...

Apr 15, 2024
CVE-2024-29841
7.5

The Evolution Controller web interface contains an access control vulnerability in the DESKTOP_EDIT_USER_GET_KEYS_FIELDS endpoint that allows unauthen...

Apr 15, 2024
CVE-2023-51142
7.5

This vulnerability in ZKTeco BioTime allows remote attackers to access sensitive information without authentication. It affects BioTime versions 8.5.4...

Apr 11, 2024
CVE-2024-31817
7.5

This vulnerability in TOTOLINK EX200 routers allows attackers to access sensitive system configuration information without authentication through the ...

Apr 8, 2024
CVE-2024-27897
7.5

This CVE describes an input verification vulnerability in the call module that could allow unauthorized access to sensitive information. The vulnerabi...

Apr 8, 2024
CVE-2023-52341
7.5

This vulnerability in Unisoc chipsets allows remote attackers to intercept sensitive information before security activation during cellular network co...

Apr 8, 2024
CVE-2024-30571
7.5

This vulnerability allows unauthenticated attackers to access sensitive information from Netgear R6850 routers via the BRS_top.html component. It affe...

Apr 3, 2024
CVE-2024-25734
7.5

This vulnerability allows remote attackers to enumerate valid user accounts on WyreStorm Apollo VX20 devices by observing TELNET service behavior. The...

Mar 27, 2024
CVE-2024-2632
7.5

An information exposure vulnerability in Meta4 HR allows unauthenticated attackers to access sensitive system information via a specific JSP endpoint....

Mar 19, 2024
CVE-2023-40278
7.5

This vulnerability in OpenClinic GA allows attackers to determine whether specific appointments exist by manipulating the AppointmentUid parameter in ...

Mar 19, 2024
CVE-2024-28340
7.5

This vulnerability allows unauthenticated attackers to access sensitive information from Netgear CBR40, CBK40, and CBK43 routers via the currentsettin...

Mar 12, 2024
CVE-2024-24765
7.5

CVE-2024-24765 is a path traversal vulnerability in CasaOS-UserService that allows unauthorized file access due to insufficient URL filtering for avat...

Mar 6, 2024
CVE-2024-27356
7.5

This vulnerability allows attackers to download files including logs from affected GL-iNet devices via commands, potentially exposing sensitive user i...

Feb 27, 2024
CVE-2024-24309
7.5

This vulnerability in the Ecomiz Survey TMA module for PrestaShop allows unauthenticated guests to download personal information without authorization...

Feb 23, 2024
CVE-2024-26136
7.5

This CVE exposes Discord account access tokens in the config.json file of kedi ElectronCord, a Discord bot management tool. Attackers who obtain these...

Feb 20, 2024
CVE-2023-52097
7.5

This vulnerability allows attackers to bypass foreground service restrictions in Huawei's NMS module, potentially exposing sensitive service informati...

Feb 18, 2024
CVE-2023-51787
7.5

A memory leak vulnerability exists in Wind River VxWorks 7 when tasks or POSIX threads using OpenSSL exit without freeing allocated memory. This affec...

Feb 15, 2024
CVE-2023-50298
7.5

This vulnerability in Apache Solr allows attackers to steal ZooKeeper credentials and ACLs by tricking Solr into sending them to a malicious server. A...

Feb 9, 2024
CVE-2024-24304
7.5

The Mailjet module for PrestaShop before version 3.5.1 contains an information disclosure vulnerability that allows unauthenticated guests to download...

Feb 7, 2024
CVE-2024-22154
7.5

CVE-2024-22154 is an unauthenticated sensitive data exposure vulnerability in the SalesKing WordPress plugin. It allows attackers without authenticati...

Jan 24, 2024
CVE-2023-44112
7.5

This CVE describes an out-of-bounds access vulnerability in Huawei/HarmonyOS device authentication modules that could allow unauthorized access to sen...

Jan 16, 2024
CVE-2023-52190
7.5

This vulnerability allows unauthenticated attackers to access sensitive information, including personally identifiable information (PII) and coupon da...

Jan 8, 2024

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,064 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free