CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,505 vulnerabilities with CWE-200
CVE-2026-35142 LOW
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.
CVSS 2.6
CVE-2026-35140 LOW
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
CVSS 3.0
CVE-2026-55608 MEDIUM
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
CVSS 4.2
CVE-2026-52888 MEDIUM
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
CVSS 6.8
CVE-2026-45737 MEDIUM
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
CVSS 6.3
CVE-2026-40956 LOW
Memory disclosure in Secure Access Clients
CVSS 3.7
CVE-2026-49988 MEDIUM
Repomix: attach_packed_output can bypass file-read secret scanning for supported local files
CVE-2026-20298 MEDIUM
Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
CVSS 5.3
CVE-2026-45793 HIGH
Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
CVSS 7.5
CVE-2026-58554 MEDIUM
Huawei HarmonyOS - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.6
CVE-2026-13230 MEDIUM
TP-Link Kasa EC70 and EC71 Local Discovery - Unauthenticated Geolocation Disclosure
CVE-2026-52101 CRITICAL
linx-server 1.0-2.3.8 - Unauthenticated Sensitive Information Disclosure via uploadRemote Function in upload.go
CVSS 9.1
CVE-2026-49853 HIGH
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
CVSS 7.7
CVE-2026-48001 LOW
Adobe Commerce | Information Exposure (CWE-200)
CVSS 3.7
CVE-2026-15642 LOW
Devolutions Server - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 3.3
CVE-2026-57102 HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 8.8
CVE-2026-57095 MEDIUM
Microsoft Windows 10 Version 1607 - Win32k Elevation of Privilege Vulnerability
CVSS 6.2
CVE-2026-56184 MEDIUM
Microsoft Windows Win32K - Local Information Disclosure
CVSS 5.5
CVE-2026-50681 MEDIUM
Microsoft Windows 10 Version 1607 - Windows Secure Channel Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-50483 MEDIUM
Microsoft Windows 11 Version 24H2 - Windows Graphics Component Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-50473 MEDIUM
Microsoft Windows 10 Version 1607 - Windows File Explorer Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-50456 MEDIUM
Microsoft Windows 10 Version 1607 - Windows File Explorer Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-50442 MEDIUM
Microsoft Windows 10 Version 1607 - Windows File Explorer Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-50434 MEDIUM
Microsoft Windows 10 Version 21H2 - Windows Push Notification Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-50431 MEDIUM
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
CVSS 5.5
Details
Vulnerabilities 10,505
Exploit Likelihood High