CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,512 vulnerabilities with CWE-200
CVE-2026-57994 MEDIUM
phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints
CVSS 5.3
CVE-2026-15329 MEDIUM
zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure
CVSS 4.3
CVE-2026-59828 MEDIUM
Discourse: Hidden post revisions leak through adjacent visible diffs
CVSS 5.3
CVE-2026-49256 HIGH
Discourse: Hidden tag names leaked via category serializers
CVSS 7.5
CVE-2026-45788 HIGH
Discourse: Secure uploads exposed by hotlinked image copying
CVSS 7.5
CVE-2026-45780 MEDIUM
Discourse: Private event sample invitees are serialized to non-invited event viewers
CVSS 5.3
CVE-2026-59720 HIGH
Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server
CVSS 7.5
CVE-2026-59222 MEDIUM
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVSS 6.5
CVE-2026-59216 HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
CVE-2026-59209 MEDIUM
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVSS 6.5
CVE-2026-57481 LOW
Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change
CVE-2026-15044 MEDIUM
Trustyai-service-operator: trustyai service operator: unauthenticated access to ai guardrails and orchestrator apis
CVSS 6.3
CVE-2026-56298 MEDIUM
Capgo - EXIF Metadata Exposure in App Information Image Upload
CVSS 4.3
CVE-2026-56284 MEDIUM
Capgo - Unauthenticated Metrics Disclosure via get_total_metrics RPC
CVSS 5.3
CVE-2026-56226 HIGH
Capgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPC
CVSS 7.5
CVE-2026-44877 MEDIUM
Hewlett Packard Enterprise (HPE) HPE Networking Instant On - Unauthenticated Remote Disclosure of Cryptographic Secrets
CVSS 6.5
CVE-2026-49487 MEDIUM
Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
CVSS 6.5
CVE-2026-48892 MEDIUM
Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options
CVSS 6.5
CVE-2026-48891 MEDIUM
Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target
CVSS 4.3
CVE-2026-48828 MEDIUM
Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key
CVSS 6.5
CVE-2026-53647 MEDIUM
FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint
CVE-2026-53643 HIGH
FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints
CVE-2026-53640 LOW
FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data
CVE-2026-14898 MEDIUM
Openai Codex Desktop App For macOS < 26.527.31326 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
CVE-2026-55994 HIGH
Apache Camel Iggy - Server-Side Request Forgery via Iggy User Headers
CVSS 7.5
Details
Vulnerabilities 10,512
Exploit Likelihood High