CWE-200
High likelihoodExposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
10,512 vulnerabilities with CWE-200
CVE-2026-57994
MEDIUM
phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints
CVSS 5.3
CVE-2026-15329
MEDIUM
zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure
CVSS 4.3
CVE-2026-59828
MEDIUM
Discourse: Hidden post revisions leak through adjacent visible diffs
CVSS 5.3
CVE-2026-49256
HIGH
Discourse: Hidden tag names leaked via category serializers
CVSS 7.5
CVE-2026-45788
HIGH
Discourse: Secure uploads exposed by hotlinked image copying
CVSS 7.5
CVE-2026-45780
MEDIUM
Discourse: Private event sample invitees are serialized to non-invited event viewers
CVSS 5.3
CVE-2026-59720
HIGH
Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server
CVSS 7.5
CVE-2026-59222
MEDIUM
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVSS 6.5
CVE-2026-59216
HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
CVE-2026-59209
MEDIUM
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVSS 6.5
CVE-2026-57481
LOW
Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change
CVE-2026-15044
MEDIUM
Trustyai-service-operator: trustyai service operator: unauthenticated access to ai guardrails and orchestrator apis
CVSS 6.3
CVE-2026-56298
MEDIUM
Capgo - EXIF Metadata Exposure in App Information Image Upload
CVSS 4.3
CVE-2026-56284
MEDIUM
Capgo - Unauthenticated Metrics Disclosure via get_total_metrics RPC
CVSS 5.3
CVE-2026-56226
HIGH
Capgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPC
CVSS 7.5
CVE-2026-44877
MEDIUM
Hewlett Packard Enterprise (HPE) HPE Networking Instant On - Unauthenticated Remote Disclosure of Cryptographic Secrets
CVSS 6.5
CVE-2026-49487
MEDIUM
Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
CVSS 6.5
CVE-2026-48892
MEDIUM
Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options
CVSS 6.5
CVE-2026-48891
MEDIUM
Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target
CVSS 4.3
CVE-2026-48828
MEDIUM
Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key
CVSS 6.5
CVE-2026-53647
MEDIUM
FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint
CVE-2026-53643
HIGH
FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints
CVE-2026-53640
LOW
FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data
CVE-2026-14898
MEDIUM
Openai Codex Desktop App For macOS < 26.527.31326 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
CVE-2026-55994
HIGH
Apache Camel Iggy - Server-Side Request Forgery via Iggy User Headers
CVSS 7.5
Details
Vulnerabilities
10,512
Exploit Likelihood
High