CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,512 vulnerabilities with CWE-200
CVE-2026-55993 HIGH
Apache Camel Atmosphere Websocket - Server-Side Request Forgery via Query Parameters
CVSS 7.5
CVE-2026-46726 HIGH
Apache Camel Vertx Websocket - Server-Side Request Forgery via Query Parameters
CVSS 7.5
CVE-2026-46584 LOW
Apache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters
CVSS 3.7
CVE-2026-58419 HIGH
Notification API leaks private issue metadata after access revocation
CVSS 7.5
CVE-2026-56646 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVSS 6.5
CVE-2026-25038 HIGH
Gitea private organization labels are visible to unauthorized users
CVSS 7.5
CVE-2026-24451 HIGH
Gitea fork synchronization can expose private parent repository data
CVSS 7.5
CVE-2026-14611 MEDIUM
DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resource
CVSS 4.3
CVE-2026-10055 HIGH
Eclipse Theia < 1.73.0 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 8.5
CVE-2026-55792 MEDIUM
Craft CMS: Sensitive File Disclosure / Server-Side File Read
CVE-2026-53467 MEDIUM
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
CVSS 5.3
CVE-2026-58036 HIGH
Users API leaks whether privileged users have their user groups disabled for lack of 2FA
CVSS 7.5
CVE-2026-58033 MEDIUM
MediaWiki InfoAction - Deleted Author Name Exposure
CVSS 6.5
CVE-2026-58027 MEDIUM
MediaWiki AbuseFilter API - Private Filter Hit Count Disclosure
CVSS 6.5
CVE-2026-58026 MEDIUM
$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces
CVSS 5.7
CVE-2026-58024 MEDIUM
Wikimedia Foundation MediaWiki - API Identification of Users on Private Wikis
CVSS 5.7
CVE-2026-12408 MEDIUM
Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter
CVSS 4.3
CVE-2026-56318 MEDIUM
Capgo - Information Disclosure via /private/validate_password_compliance Endpoint
CVSS 5.3
CVE-2026-56300 HIGH
Capgo - Unauthenticated API Key Validity and Permission Oracle via RPC Functions
CVSS 7.5
CVE-2026-54673 HIGH
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
CVE-2026-14146 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via CSS
CVSS 6.5
CVE-2026-14098 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via CSS Implementation
CVSS 6.5
CVE-2026-14096 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Input Implementation
CVSS 6.5
CVE-2026-14062 MEDIUM
Google Chrome on ChromeOS < 150.0.7871.47 - Information Disclosure via Malicious Extension
CVSS 5.9
CVE-2026-14049 MEDIUM
Google Chrome < 150.0.7871.47 - Information Disclosure via GPU Memory Access
CVSS 5.3
Details
Vulnerabilities 10,512
Exploit Likelihood High