CWE-200: Information Exposure

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

1,064
Total CVEs
91
Critical
389
High
6.5
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
132
2025
470
2024
275
2023
92
2022
41

Top Affected Vendors

1 Apple 81
2 Microsoft 46
3 Huawei 34
4 Apache 25
5 Oracle 19
6 Google 15
7 Debian 12
8 Splunk 9
9 Mozilla 9
10 Netgear 8

All Information Exposure CVEs (1,064)

CVE-2021-34125
7.5

This vulnerability allows attackers to execute NuttX commands on Yuneec Mantis Q drones and PX4-Autopilot systems, potentially exposing sensitive info...

Mar 9, 2023
CVE-2023-26476
7.5

This vulnerability in XWiki Platform allows attackers to deduce password field contents through repeated calls to LiveTableResults and WikisLiveTableR...

Mar 2, 2023
CVE-2023-25544
7.5

Dell NetWorker versions 19.5 and earlier expose Apache Tomcat version information, allowing attackers to fingerprint the software. This vulnerability ...

Mar 1, 2023
CVE-2023-0994
7.5

This CVE describes an information exposure vulnerability in RosarioSIS, an open-source student information system. The vulnerability allows unauthoriz...

Feb 24, 2023
CVE-2022-45454
7.5

This vulnerability allows local users to access sensitive information due to insecure folder permissions in Acronis products on Windows. It affects Ac...

Feb 13, 2023
CVE-2022-31162
7.5

Slack Morphism Rust library versions before 0.41.0 could leak Slack OAuth client secrets in debug logs. This exposes authentication credentials that c...

Jul 22, 2022
CVE-2022-31308
7.5

This vulnerability in WAVLINK AERIAL X 1200M routers allows attackers to execute commands via the live_mfg.shtml page, exposing sensitive router infor...

Jun 14, 2022
CVE-2022-32192
7.5

Couchbase Server versions 5.x through 7.x before 7.0.4 expose sensitive information to unauthorized actors. This information disclosure vulnerability ...

Jun 13, 2022
CVE-2022-29244
7.5

This vulnerability in npm causes workspace operations to ignore .gitignore and .npmignore exclusion rules, potentially exposing sensitive files. Anyon...

Jun 13, 2022
CVE-2022-31042
7.5

Guzzle HTTP client versions before 6.5.7 and 7.4.4 expose sensitive cookie information during HTTP redirects. When a request to an HTTPS server redire...

Jun 10, 2022
CVE-2017-20022
7.5

This vulnerability in Solar-Log monitoring systems allows remote attackers to access sensitive information without authentication. It affects Solar-Lo...

Jun 9, 2022
CVE-2022-30556
7.5

CVE-2022-30556 is a buffer overflow vulnerability in Apache HTTP Server's r:wsread() function that can cause memory corruption. It affects Apache HTTP...

Jun 9, 2022
CVE-2021-42886
7.5

CVE-2021-42886 allows unauthenticated attackers to download the apmib configuration file from TOTOLINK EX1200T routers, exposing usernames and passwor...

Jun 3, 2022
CVE-2022-27775
7.5

This curl vulnerability allows information disclosure when an attacker can force curl to reuse an existing IPv6 connection from the pool with a differ...

Jun 2, 2022
CVE-2022-1815
7.5

CVE-2022-1815 is an information disclosure vulnerability in draw.io diagramming software that exposes sensitive information to unauthorized actors. Th...

May 25, 2022
CVE-2022-24867
7.5

CVE-2022-24867 is an information disclosure vulnerability in GLPI where the LDAP password is exposed in rendered page source code due to insufficient ...

Apr 21, 2022
CVE-2021-43287
7.5

CVE-2021-43287 is a critical information disclosure vulnerability in ThoughtWorks GoCD's business continuity add-on. Unauthenticated attackers can exp...

Apr 14, 2022
CVE-2022-27667
7.5

CVE-2022-27667 is an information disclosure vulnerability in SAP BusinessObjects Business Intelligence platform's Client Management Console (CMC). It ...

Apr 12, 2022
CVE-2022-27241
7.5

This vulnerability in Mendix applications exposes internal project structure information to unauthenticated remote attackers. It affects Mendix applic...

Apr 12, 2022
CVE-2019-14839
7.5

CVE-2019-14839 is an information disclosure vulnerability in Business-central console where HTTP requests expose login credentials during authenticati...

Apr 1, 2022
CVE-2021-27422
7.5

GE UR firmware versions prior to 8.1x expose sensitive information through the web server interface without requiring authentication. This vulnerabili...

Mar 23, 2022
CVE-2022-25512
7.5

FreeTAKServer-UI v1.9.8 leaks sensitive API and Websocket keys, potentially exposing authentication credentials and allowing unauthorized access to se...

Mar 11, 2022
CVE-2022-0725
7.5

CVE-2022-0725 is an information exposure vulnerability in KeePass where plain text passwords are logged to system logs. This allows attackers with acc...

Mar 10, 2022
CVE-2022-23648
7.5

This vulnerability in containerd allows containers with specially-crafted image configurations to access read-only copies of arbitrary host files and ...

Mar 3, 2022
CVE-2021-4076
7.5

A vulnerability in tang (network-based cryptographic binding server) allows private key leakage through improper handling of cryptographic operations....

Mar 2, 2022
CVE-2022-21712
7.5

This vulnerability in the Twisted Python networking engine exposes sensitive authentication data (cookies and authorization headers) when following cr...

Feb 7, 2022
CVE-2021-38960
7.5

This vulnerability in IBM OPENBMC OP920, OP930, and OP940 allows unauthenticated attackers to access sensitive information without credentials. It aff...

Feb 4, 2022
CVE-2022-0281
7.5

CVE-2022-0281 is an information disclosure vulnerability in Microweber CMS that exposes sensitive information to unauthorized actors. This affects all...

Jan 20, 2022
CVE-2021-37125
7.5

CVE-2021-37125 is an information disclosure vulnerability in HarmonyOS that allows unauthorized actors to access sensitive files. This affects Harmony...

Jan 3, 2022
CVE-2021-37010
7.5

This CVE describes an information exposure vulnerability in Huawei smartphones running HarmonyOS. It allows unauthorized actors to access sensitive us...

Nov 23, 2021
CVE-2021-30284
7.5

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to potentially expose sensitive information or cause denial of service by exploiti...

Nov 12, 2021
CVE-2021-42089
7.5

This vulnerability in Zammad's REST API allows unauthorized disclosure of sensitive information. Attackers can access confidential data through API en...

Oct 7, 2021
CVE-2021-41109
7.5

Parse Server versions before 4.10.4 expose user session tokens in LiveQuery payloads when users subscribe to Parse.User class updates. This allows att...

Sep 30, 2021
CVE-2021-41082
7.5

Discourse had a vulnerability where private message titles and participant lists were exposed to unauthorized users when groups were included in messa...

Sep 20, 2021
CVE-2021-21817
7.5

This vulnerability in D-LINK DIR-3040 routers allows attackers to obtain sensitive information through specially crafted network requests to the Zebra...

Jul 16, 2021
CVE-2021-35527
7.5

This CVE describes a password autocomplete vulnerability in Hitachi ABB Power Grids eSOMS web application that allows attackers to access user credent...

Jul 14, 2021
CVE-2021-25426
7.5

This vulnerability in Samsung's Message app allows untrusted applications to access message files due to improper component protection in SmsViewerAct...

Jul 8, 2021
CVE-2021-20019
7.5

CVE-2021-20019 is a memory disclosure vulnerability in SonicOS HTTP servers where crafted HTTP requests can leak partial memory contents. This could e...

Jun 23, 2021
CVE-2010-1432
7.5

Joomla! Core 1.5.x has an information disclosure vulnerability where attackers can use negative values for limit and offset parameters to access sensi...

Jun 21, 2021
CVE-2021-23937
7.5

This vulnerability in Apache Wicket allows attackers to trigger arbitrary DNS lookups from the server by manipulating the X-Forwarded-For header. This...

May 25, 2021
CVE-2021-32624
7.5

Keystone 5 CMS has an access control bypass vulnerability that allows attackers to extract private field values through query infrastructure manipulat...

May 24, 2021
CVE-2021-27434
7.5

This vulnerability in Unified Automation .NET based OPC UA Client/Server SDK allows attackers to trigger a stack overflow via uncontrolled recursion. ...

May 20, 2021
CVE-2021-31918
7.5

This vulnerability exposes Ansible log files to all users during OpenStack stack operations, potentially revealing sensitive configuration data and cr...

May 6, 2021
CVE-2021-24226
7.5

This vulnerability allows unauthenticated attackers to view sensitive server environment variables on any public WordPress page containing the [access...

Apr 12, 2021
CVE-2021-24167
7.5

This vulnerability in Web-Stat WordPress plugin versions before 1.4.0 allows information disclosure through client-side requests. When visitors access...

Apr 5, 2021
CVE-2021-24170
7.5

The User Profile Picture WordPress plugin before version 2.5.0 exposed sensitive user data through its REST API endpoint. Users with upload_files capa...

Apr 5, 2021
CVE-2021-26923
7.5

CVE-2021-26923 is an information disclosure vulnerability in Argo CD where the /api/version endpoint leaks internal system information without requiri...

Mar 15, 2021
CVE-2021-25122
7.5

This vulnerability in Apache Tomcat allows HTTP/2 cleartext (h2c) connections to leak request data between users. When processing h2c requests, Tomcat...

Mar 1, 2021
CVE-2020-11281
7.5

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to link RTT (Round Trip Time) frames by comparing sequence numbers when non-random...

Feb 22, 2021
CVE-2021-21469
7.5

This vulnerability in SAP NetWeaver Master Data Management allows attackers to set custom UNC paths in MDS server configuration, potentially enabling ...

Jan 12, 2021

About Information Exposure (CWE-200)

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Our database tracks 1,064 CVEs classified as CWE-200, with 91 rated critical and 389 rated high severity. The average CVSS score for Information Exposure vulnerabilities is 6.5.

External reference: View CWE-200 on MITRE CWE →

Monitor Information Exposure Vulnerabilities

Get alerted when new Information Exposure CVEs affect your infrastructure.

Start Monitoring Free