CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,504 vulnerabilities with CWE-200
CVE-2026-55496 MEDIUM
Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate
CVSS 4.3
CVE-2026-67529 MEDIUM
OpenProject < 17.6.0 - Private Work Package Information Disclosure
CVSS 4.3
CVE-2026-10569 MEDIUM
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability
CVSS 4.3
CVE-2026-48499 CRITICAL
Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
CVE-2026-41186 MEDIUM
Unauthenticated Go pprof exposure in Calico debug server
CVE-2026-15235 MEDIUM
Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
CVSS 4.3
CVE-2026-14231 MEDIUM
LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts
CVSS 4.3
CVE-2026-14226 MEDIUM
Easy Appointments <= 3.12.26 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing
CVSS 4.3
CVE-2026-14188 LOW
Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure
CVSS 2.7
CVE-2026-18011 LOW
Google Chrome for iOS < 151.0.7922.72 - Local Information Disclosure via Physical Access
CVSS 2.4
CVE-2026-18005 MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via WebXR Implementation
CVSS 6.5
CVE-2026-18001 MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via WebGL Implementation
CVSS 6.5
CVE-2026-17975 MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via IME Implementation on Mac
CVSS 6.5
CVE-2026-17973 MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via Crafted HTML Page in Views on macOS
CVSS 5.5
CVE-2026-17966 MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via Crafted HTML Page in Views on macOS
CVSS 6.2
CVE-2026-17928 MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via DataTransfer Inappropriate Implementation
CVSS 4.3
CVE-2026-17902 LOW
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Editing Implementation on Linux
CVSS 3.5
CVE-2026-17892 MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via WebXR Implementation
CVSS 6.5
CVE-2026-17683 MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via ANGLE Inappropriate Implementation
CVSS 6.5
CVE-2026-67436 HIGH
Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins
CVE-2026-67435 MEDIUM
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
CVE-2026-13697 HIGH
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVSS 7.4
CVE-2026-54660 HIGH
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVSS 7.4
CVE-2026-66489 MEDIUM
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVSS 5.3
CVE-2026-58157 HIGH
Apache Traffic Server: Improper server-session reuse can expose data across client connections
CVSS 8.7
Details
Vulnerabilities 10,504
Exploit Likelihood High