CWE-200: Information Exposure
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Yearly Trend
Top Affected Vendors
All Information Exposure CVEs (1,064)
This vulnerability in Apache OFBiz allows unauthenticated attackers to read arbitrary file properties via unauthorized URI calls, potentially exposing...
Dec 26, 2023This vulnerability allows unauthorized actors to access sensitive information from resume files uploaded through the JobWP WordPress plugin. It affect...
Dec 21, 2023This vulnerability in the ProfilePress WordPress plugin exposes sensitive information via debug logs to unauthorized actors. It affects all WordPress ...
Nov 30, 2023This vulnerability in the WordPress Post Grid Combo plugin allows unauthorized actors to access sensitive information. It affects all WordPress sites ...
Nov 30, 2023Apache DolphinScheduler versions before 3.2.1 expose sensitive information to unauthorized actors through improper log handling. This vulnerability al...
Nov 27, 2023This vulnerability in Label Studio allows attackers to exploit insecure filter chains to leak sensitive user data character by character through Djang...
Nov 13, 2023CVE-2023-45875 is a private key leak vulnerability in Couchbase Server 7.2.0 where sensitive cryptographic keys are exposed in debug.log files when ad...
Nov 8, 2023This vulnerability in Huawei's remote PIN module involves incorrect information storage locations that could expose sensitive data. It affects Huawei ...
Nov 8, 2023This CVE describes a missing encryption vulnerability in Huawei's card management module that could allow unauthorized access to sensitive card data. ...
Nov 8, 2023This vulnerability in Best Practical Request Tracker (RT) allows attackers to access sensitive information through the transaction search feature in t...
Nov 3, 2023This vulnerability in Best Practical Request Tracker (RT) exposes sensitive information through responses to mail-gateway REST API calls. Attackers ca...
Nov 3, 2023CVE-2023-39057 is an information disclosure vulnerability in hirochanKAKIwaiting v13.6.1 that allows attackers to leak the channel access token. This ...
Nov 2, 2023CVE-2023-39047 is an information disclosure vulnerability in shouzu sweets oz v13.6.1 that allows attackers to obtain channel access tokens. This enab...
Nov 2, 2023CVE-2023-39050 is an information disclosure vulnerability in Daiky-value.Fukueten v13.6.1 that allows attackers to obtain channel access tokens. This ...
Nov 2, 2023CVE-2023-39053 is an information disclosure vulnerability in Hattoriya v13.6.1 that allows attackers to leak the channel access token. This enables un...
Nov 2, 2023This vulnerability in Ocomon's users-grid-data.php component allows attackers to access sensitive user information including emails and usernames with...
Oct 26, 2023CVE-2023-38846 is an information disclosure vulnerability in Marbre Lapin Line v.13.6.1 that allows remote attackers to access sensitive information t...
Oct 25, 2023EisBaer Scada systems expose sensitive information to unauthorized actors, allowing attackers to access confidential data without authentication. This...
Oct 25, 2023This vulnerability in the Infinite Image Browsing extension for Stable Diffusion web UI allows remote attackers to read any local file on the server w...
Oct 22, 2023This vulnerability in Oracle HTTP Server allows unauthenticated attackers with network access via HTTP to access sensitive data. It affects Oracle Fus...
Oct 17, 2023Apache Traffic Server versions 8.0.0-8.1.8 and 9.0.0-9.2.2 expose sensitive information to unauthorized actors. This CWE-200 vulnerability allows atta...
Oct 17, 2023Discourse chat messages can be read by unauthenticated attackers via a POST request to MessageBus, exposing private conversations. This affects all Di...
Oct 16, 2023This vulnerability in Huawei's security module fails to verify package names' public keys, allowing attackers to potentially install malicious package...
Oct 11, 2023Drupal's JSON:API module can expose sensitive error backtraces that may be cached and accessible to anonymous users. This information disclosure vulne...
Sep 28, 2023This vulnerability allows unauthenticated attackers to access PHP configuration information via the send.php file in affected Prestashop modules. It e...
Sep 20, 2023This vulnerability in TDSQL Chitu management platform allows remote attackers to access sensitive database information through an unsecured function i...
Sep 18, 2023This vulnerability in the GitHub repository hamza417/inure exposes sensitive information to unauthorized actors. It affects users of this repository p...
Sep 10, 2023This vulnerability in Acronis Agent and Cyber Protect for Windows allows attackers to access sensitive system information through excessive data colle...
Aug 31, 2023This vulnerability in Mitel MiVoice Connect's Connect Mobility Router allows unauthenticated attackers to conduct account enumeration attacks due to i...
Aug 25, 2023Cloud Explorer Lite versions before 1.4.0 contain an information disclosure vulnerability in user information acquisition functionality. This allows a...
Aug 24, 2023CVE-2023-25913 is an authentication flaw that allows attackers to generate web reports containing sensitive information like internal IP addresses, us...
Aug 21, 2023CVE-2023-40735 is an information disclosure vulnerability in the Cavo BUTTERFLY BUTTON architecture that exposes sensitive information to unauthorized...
Aug 21, 2023This vulnerability involves insecure signature verification in Huawei's ServiceWifiResources module, allowing attackers to maliciously modify and over...
Aug 13, 2023This vulnerability in TeamPass (a password manager) allows unauthorized actors to access sensitive information stored in the application. It affects a...
Jul 8, 2023This CVE-2022-48514 vulnerability in the Sepolicy module allows inappropriate permission control on Netlink usage, potentially enabling unauthorized a...
Jul 6, 2023This vulnerability in Huawei's DSoftBus module allows third-party apps to obtain unique values, potentially exposing sensitive information. It affects...
Jul 6, 2023CVE-2022-48519 is an unauthorized access vulnerability in Huawei's SystemUI module that allows attackers to bypass intended access restrictions. This ...
Jul 6, 2023A format string vulnerability exists in Huawei's distributed file system that could allow attackers to crash the program. This affects Huawei devices ...
Jul 6, 2023Apache Traffic Server versions 8.0.0 through 9.2.0 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive...
Jun 14, 2023Apache Traffic Server versions 8.0.0 through 9.2.0 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive...
Jun 14, 2023This vulnerability allows anonymous users to enumerate all user accounts managed by the Mobatime mobile application. This information disclosure could...
Jun 5, 2023This vulnerability allows unauthenticated attackers to access the config.json file in ChuanhuChatGPT deployments without authentication configured. Th...
Jun 2, 2023OpenProject's robots.txt file publicly exposes project identifiers even when the entire instance is configured to require login. This information disc...
Jun 1, 2023CVE-2023-31185 is a misconfiguration vulnerability in ROZCOM server framework that allows attackers to disclose sensitive information through unspecif...
May 30, 2023This vulnerability in SAP GUI for Windows allows attackers to steal NTLM authentication credentials by tricking users into clicking malicious shortcut...
May 9, 2023This vulnerability in Ghost CMS allows attackers to brute-force filter parameters on public API endpoints to reveal private fields like passwords and ...
May 8, 2023CVE-2022-48346 is a logic bypass vulnerability in Huawei's HwContacts module that could allow unauthorized access to contact information. This affects...
Mar 27, 2023This CVE describes an information disclosure vulnerability in the Android kernel that could allow local attackers to access sensitive information with...
Mar 24, 2023MinIO distributed deployments expose all environment variables including sensitive credentials like MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD through a...
Mar 22, 2023This vulnerability allows unauthenticated attackers to access Prometheus metrics from publicly exposed Miniflux instances with metrics collection enab...
Mar 17, 2023About Information Exposure (CWE-200)
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Our database tracks 1,064 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.
External reference: View CWE-200 on MITRE CWE →
Monitor Information Exposure Vulnerabilities
Get alerted when new Information Exposure CVEs affect your infrastructure.
Start Monitoring Free