CWE-200
High likelihoodExposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
10,504 vulnerabilities with CWE-200
CVE-2026-55496
MEDIUM
Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate
CVSS 4.3
CVE-2026-67529
MEDIUM
OpenProject < 17.6.0 - Private Work Package Information Disclosure
CVSS 4.3
CVE-2026-10569
MEDIUM
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability
CVSS 4.3
CVE-2026-48499
CRITICAL
Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache
CVE-2026-41186
MEDIUM
Unauthenticated Go pprof exposure in Calico debug server
CVE-2026-15235
MEDIUM
Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
CVSS 4.3
CVE-2026-14231
MEDIUM
LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts
CVSS 4.3
CVE-2026-14226
MEDIUM
Easy Appointments <= 3.12.26 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing
CVSS 4.3
CVE-2026-14188
LOW
Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure
CVSS 2.7
CVE-2026-18011
LOW
Google Chrome for iOS < 151.0.7922.72 - Local Information Disclosure via Physical Access
CVSS 2.4
CVE-2026-18005
MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via WebXR Implementation
CVSS 6.5
CVE-2026-18001
MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via WebGL Implementation
CVSS 6.5
CVE-2026-17975
MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via IME Implementation on Mac
CVSS 6.5
CVE-2026-17973
MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via Crafted HTML Page in Views on macOS
CVSS 5.5
CVE-2026-17966
MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via Crafted HTML Page in Views on macOS
CVSS 6.2
CVE-2026-17928
MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via DataTransfer Inappropriate Implementation
CVSS 4.3
CVE-2026-17902
LOW
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Editing Implementation on Linux
CVSS 3.5
CVE-2026-17892
MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via WebXR Implementation
CVSS 6.5
CVE-2026-17683
MEDIUM
Google Chrome < 151.0.7922.72 - Information Disclosure via ANGLE Inappropriate Implementation
CVSS 6.5
CVE-2026-67436
HIGH
Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins
CVE-2026-67435
MEDIUM
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
CVE-2026-13697
HIGH
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVSS 7.4
CVE-2026-54660
HIGH
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVSS 7.4
CVE-2026-66489
MEDIUM
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVSS 5.3
CVE-2026-58157
HIGH
Apache Traffic Server: Improper server-session reuse can expose data across client connections
CVSS 8.7
Details
Vulnerabilities
10,504
Exploit Likelihood
High