CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,064
Total CVEs
91
Critical
389
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
132
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,064)

CVE-2023-50968
7.5

This vulnerability in Apache OFBiz allows unauthenticated attackers to read arbitrary file properties via unauthorized URI calls, potentially exposing...

Dec 26, 2023
CVE-2023-48288
7.5

This vulnerability allows unauthorized actors to access sensitive information from resume files uploaded through the JobWP WordPress plugin. It affect...

Dec 21, 2023
CVE-2023-44150
7.5

This vulnerability in the ProfilePress WordPress plugin exposes sensitive information via debug logs to unauthorized actors. It affects all WordPress ...

Nov 30, 2023
CVE-2023-40211
7.5

This vulnerability in the WordPress Post Grid Combo plugin allows unauthorized actors to access sensitive information. It affects all WordPress sites ...

Nov 30, 2023
CVE-2023-49068
7.5

Apache DolphinScheduler versions before 3.2.1 expose sensitive information to unauthorized actors through improper log handling. This vulnerability al...

Nov 27, 2023
CVE-2023-47117
7.5

This vulnerability in Label Studio allows attackers to exploit insecure filter chains to leak sensitive user data character by character through Djang...

Nov 13, 2023
CVE-2023-45875
7.5

CVE-2023-45875 is a private key leak vulnerability in Couchbase Server 7.2.0 where sensitive cryptographic keys are exposed in debug.log files when ad...

Nov 8, 2023
CVE-2023-46757
7.5

This vulnerability in Huawei's remote PIN module involves incorrect information storage locations that could expose sensitive data. It affects Huawei ...

Nov 8, 2023
CVE-2023-44098
7.5

This CVE describes a missing encryption vulnerability in Huawei's card management module that could allow unauthorized access to sensitive card data. ...

Nov 8, 2023
CVE-2023-45024
7.5

This vulnerability in Best Practical Request Tracker (RT) allows attackers to access sensitive information through the transaction search feature in t...

Nov 3, 2023
CVE-2023-41260
7.5

This vulnerability in Best Practical Request Tracker (RT) exposes sensitive information through responses to mail-gateway REST API calls. Attackers ca...

Nov 3, 2023
CVE-2023-39057
7.5

CVE-2023-39057 is an information disclosure vulnerability in hirochanKAKIwaiting v13.6.1 that allows attackers to leak the channel access token. This ...

Nov 2, 2023
CVE-2023-39047
7.5

CVE-2023-39047 is an information disclosure vulnerability in shouzu sweets oz v13.6.1 that allows attackers to obtain channel access tokens. This enab...

Nov 2, 2023
CVE-2023-39050
7.5

CVE-2023-39050 is an information disclosure vulnerability in Daiky-value.Fukueten v13.6.1 that allows attackers to obtain channel access tokens. This ...

Nov 2, 2023
CVE-2023-39053
7.5

CVE-2023-39053 is an information disclosure vulnerability in Hattoriya v13.6.1 that allows attackers to leak the channel access token. This enables un...

Nov 2, 2023
CVE-2023-33558
7.5

This vulnerability in Ocomon's users-grid-data.php component allows attackers to access sensitive user information including emails and usernames with...

Oct 26, 2023
CVE-2023-38846
7.5

CVE-2023-38846 is an information disclosure vulnerability in Marbre Lapin Line v.13.6.1 that allows remote attackers to access sensitive information t...

Oct 25, 2023
CVE-2023-42490
7.5

EisBaer Scada systems expose sensitive information to unauthorized actors, allowing attackers to access confidential data without authentication. This...

Oct 25, 2023
CVE-2023-46315
7.5

This vulnerability in the Infinite Image Browsing extension for Stable Diffusion web UI allows remote attackers to read any local file on the server w...

Oct 22, 2023
CVE-2023-22019
7.5

This vulnerability in Oracle HTTP Server allows unauthenticated attackers with network access via HTTP to access sensitive data. It affects Oracle Fus...

Oct 17, 2023
CVE-2023-41752
7.5

Apache Traffic Server versions 8.0.0-8.1.8 and 9.0.0-9.2.2 expose sensitive information to unauthorized actors. This CWE-200 vulnerability allows atta...

Oct 17, 2023
CVE-2023-45131
7.5

Discourse chat messages can be read by unauthenticated attackers via a POST request to MessageBus, exposing private conversations. This affects all Di...

Oct 16, 2023
CVE-2023-44093
7.5

This vulnerability in Huawei's security module fails to verify package names' public keys, allowing attackers to potentially install malicious package...

Oct 11, 2023
CVE-2023-5256
7.5

Drupal's JSON:API module can expose sensitive error backtraces that may be cached and accessible to anonymous users. This information disclosure vulne...

Sep 28, 2023
CVE-2023-39677
7.5

This vulnerability allows unauthenticated attackers to access PHP configuration information via the send.php file in affected Prestashop modules. It e...

Sep 20, 2023
CVE-2023-42387
7.5

This vulnerability in TDSQL Chitu management platform allows remote attackers to access sensitive database information through an unsecured function i...

Sep 18, 2023
CVE-2023-4876
7.5

This vulnerability in the GitHub repository hamza417/inure exposes sensitive information to unauthorized actors. It affects users of this repository p...

Sep 10, 2023
CVE-2023-41749
7.5

This vulnerability in Acronis Agent and Cyber Protect for Windows allows attackers to access sensitive system information through excessive data colle...

Aug 31, 2023
CVE-2023-39289
7.5

This vulnerability in Mitel MiVoice Connect's Connect Mobility Router allows unauthenticated attackers to conduct account enumeration attacks due to i...

Aug 25, 2023
CVE-2023-39519
7.5

Cloud Explorer Lite versions before 1.4.0 contain an information disclosure vulnerability in user information acquisition functionality. This allows a...

Aug 24, 2023
CVE-2023-25913
7.5

CVE-2023-25913 is an authentication flaw that allows attackers to generate web reports containing sensitive information like internal IP addresses, us...

Aug 21, 2023
CVE-2023-40735
7.5

CVE-2023-40735 is an information disclosure vulnerability in the Cavo BUTTERFLY BUTTON architecture that exposes sensitive information to unauthorized...

Aug 21, 2023
CVE-2023-39393
7.5

This vulnerability involves insecure signature verification in Huawei's ServiceWifiResources module, allowing attackers to maliciously modify and over...

Aug 13, 2023
CVE-2023-3553
7.5

This vulnerability in TeamPass (a password manager) allows unauthorized actors to access sensitive information stored in the application. It affects a...

Jul 8, 2023
CVE-2022-48514
7.5

This CVE-2022-48514 vulnerability in the Sepolicy module allows inappropriate permission control on Netlink usage, potentially enabling unauthorized a...

Jul 6, 2023
CVE-2022-48516
7.5

This vulnerability in Huawei's DSoftBus module allows third-party apps to obtain unique values, potentially exposing sensitive information. It affects...

Jul 6, 2023
CVE-2022-48519
7.5

CVE-2022-48519 is an unauthorized access vulnerability in Huawei's SystemUI module that allows attackers to bypass intended access restrictions. This ...

Jul 6, 2023
CVE-2023-37239
7.5

A format string vulnerability exists in Huawei's distributed file system that could allow attackers to crash the program. This affects Huawei devices ...

Jul 6, 2023
CVE-2023-33933
7.5

Apache Traffic Server versions 8.0.0 through 9.2.0 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive...

Jun 14, 2023
CVE-2022-47184
7.5

Apache Traffic Server versions 8.0.0 through 9.2.0 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive...

Jun 14, 2023
CVE-2023-3064
7.5

This vulnerability allows anonymous users to enumerate all user accounts managed by the Mobatime mobile application. This information disclosure could...

Jun 5, 2023
CVE-2023-34094
7.5

This vulnerability allows unauthenticated attackers to access the config.json file in ChuanhuChatGPT deployments without authentication configured. Th...

Jun 2, 2023
CVE-2023-33960
7.5

OpenProject's robots.txt file publicly exposes project identifiers even when the entire instance is configured to require login. This information disc...

Jun 1, 2023
CVE-2023-31185
7.5

CVE-2023-31185 is a misconfiguration vulnerability in ROZCOM server framework that allows attackers to disclose sensitive information through unspecif...

May 30, 2023
CVE-2023-32113
7.5

This vulnerability in SAP GUI for Windows allows attackers to steal NTLM authentication credentials by tricking users into clicking malicious shortcut...

May 9, 2023
CVE-2023-31133
7.5

This vulnerability in Ghost CMS allows attackers to brute-force filter parameters on public API endpoints to reveal private fields like passwords and ...

May 8, 2023
CVE-2022-48346
7.5

CVE-2022-48346 is a logic bypass vulnerability in Huawei's HwContacts module that could allow unauthorized access to contact information. This affects...

Mar 27, 2023
CVE-2023-21067
7.5

This CVE describes an information disclosure vulnerability in the Android kernel that could allow local attackers to access sensitive information with...

Mar 24, 2023
CVE-2023-28432
7.5

MinIO distributed deployments expose all environment variables including sensitive credentials like MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD through a...

Mar 22, 2023
CVE-2023-27591
7.5

This vulnerability allows unauthenticated attackers to access Prometheus metrics from publicly exposed Miniflux instances with metrics collection enab...

Mar 17, 2023

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,064 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free