CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,512 vulnerabilities with CWE-200
CVE-2026-33842 MEDIUM
Microsoft Windows 10 Version 1607 - Windows File Explorer Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-55651 HIGH
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
CVSS 7.1
CVE-2026-52837 MEDIUM
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
CVE-2026-15075 HIGH
Eclipse Vert.x - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 7.5
CVE-2026-10051 HIGH
Eclipse Jetty - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 7.5
CVE-2026-15627 MEDIUM
nextlevelbuilder GoClaw tool.go handleNavigate information disclosure
CVSS 4.3
CVE-2026-12385 MEDIUM
Smart Slider 3 < 3.5.1.37 - Information Exposure
CVSS 4.3
CVE-2026-15530 MEDIUM
WuzhiCMS Attachment API index.php listimage information disclosure
CVSS 5.3
CVE-2026-56336 MEDIUM
Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint
CVSS 5.3
CVE-2026-56259 HIGH
Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution
CVSS 8.2
CVE-2026-56238 HIGH
Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint
CVSS 7.5
CVE-2026-61454 MEDIUM
Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__
CVSS 5.3
CVE-2026-61426 HIGH
PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults
CVSS 8.6
CVE-2026-56303 HIGH
Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function
CVSS 7.5
CVE-2026-6801 MEDIUM
Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter
CVSS 5.3
CVE-2026-10865 MEDIUM
Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
CVSS 5.3
CVE-2026-7544 MEDIUM
Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
CVSS 4.3
CVE-2026-12426 MEDIUM
Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
CVSS 5.3
CVE-2026-59155 MEDIUM
Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API
CVE-2026-55882 HIGH
Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
CVE-2026-57219 HIGH
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
CVSS 7.5
CVE-2026-55664 MEDIUM
Grist: Insufficient access control in the /forms endpoint exposes table metadata
CVSS 4.3
CVE-2026-57474 MEDIUM
Deloitte AI Assist for Customer information disclosure
CVSS 5.3
CVE-2026-59180 LOW
Apprise forwards configured auth headers across cross-origin HTTP redirects
CVSS 3.1
CVE-2026-55500 CRITICAL
9router < 0.4.80 - Database Export Credential Disclosure and Import Overwrite
CVSS 9.9
Details
Vulnerabilities 10,512
Exploit Likelihood High