CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,512 vulnerabilities with CWE-200
CVE-2026-14004 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via CSS Implementation
CVSS 6.5
CVE-2026-13810 MEDIUM
Google Chrome < 150.0.7871.47 - Information Disclosure via Input Handling
CVSS 6.5
CVE-2026-9836 LOW
IBM DataStage Flow Designer application is affected by an information disclosure vulnerability
CVSS 3.5
CVE-2026-14161 HIGH
Advantech|Hospital Queuing Management - Sensitive Data Exposure
CVSS 7.5
CVE-2026-46406 MEDIUM
Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
CVSS 6.1
CVE-2026-49984 HIGH
Kestra LocalStorage - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-55188 HIGH
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
CVSS 8.2
CVE-2026-49355 MEDIUM
OpenProject: Private work package data disclosure through single meeting agenda item API
CVSS 4.3
CVE-2026-47193 HIGH
OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks
CVSS 7.5
CVE-2026-44736 MEDIUM
OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
CVSS 6.5
CVE-2026-57231 HIGH
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVSS 7.5
CVE-2026-37452 HIGH
MSI NBFoundation Service 2.0.2506.1201 - Insecure Permissions Information Disclosure via MSIAPService.exe
CVSS 7.5
CVE-2026-37454 HIGH
MSI NBFoundation Service 2.0.2506.1201 - Insecure Permissions via 3DES-ECB Encryption
CVSS 7.5
CVE-2026-37453 HIGH
MSI NBFoundation Service 2.0.2506.1201 - Insecure Permissions via MSI_SERVICE_2 Pipe
CVSS 7.5
CVE-2026-55180 MEDIUM
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVSS 6.5
CVE-2026-50017 MEDIUM
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVSS 6.5
CVE-2026-9153 MEDIUM
Arbitrary File Read in Rapid7 InsightConnect Sed Plugin
CVSS 6.5
CVE-2026-52815 MEDIUM
Gogs: Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-32315 MEDIUM
motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVSS 5.5
CVE-2026-47389 HIGH
Mastodon: SSRF protection bypass on older Ruby versions
CVSS 8.6
CVE-2026-53949 MEDIUM
Ghost Content API filter bypass reveals private fields
CVSS 5.3
CVE-2026-49269 HIGH
Apple M1 GPUs - Exposure of Sensitive Information via Stale Register File Data
CVSS 8.6
CVE-2026-56337 MEDIUM
Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2
CVSS 5.3
CVE-2026-56244 HIGH
Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key
CVSS 7.1
CVE-2026-9612 MEDIUM
WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs
CVSS 5.3
Details
Vulnerabilities 10,512
Exploit Likelihood High