CWE-200
High likelihoodExposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
10,512 vulnerabilities with CWE-200
CVE-2026-14004
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via CSS Implementation
CVSS 6.5
CVE-2026-13810
MEDIUM
Google Chrome < 150.0.7871.47 - Information Disclosure via Input Handling
CVSS 6.5
CVE-2026-9836
LOW
IBM DataStage Flow Designer application is affected by an information disclosure vulnerability
CVSS 3.5
CVE-2026-14161
HIGH
Advantech|Hospital Queuing Management - Sensitive Data Exposure
CVSS 7.5
CVE-2026-46406
MEDIUM
Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
CVSS 6.1
CVE-2026-49984
HIGH
Kestra LocalStorage - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-55188
HIGH
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
CVSS 8.2
CVE-2026-49355
MEDIUM
OpenProject: Private work package data disclosure through single meeting agenda item API
CVSS 4.3
CVE-2026-47193
HIGH
OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks
CVSS 7.5
CVE-2026-44736
MEDIUM
OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
CVSS 6.5
CVE-2026-57231
HIGH
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
CVSS 7.5
CVE-2026-37452
HIGH
MSI NBFoundation Service 2.0.2506.1201 - Insecure Permissions Information Disclosure via MSIAPService.exe
CVSS 7.5
CVE-2026-37454
HIGH
MSI NBFoundation Service 2.0.2506.1201 - Insecure Permissions via 3DES-ECB Encryption
CVSS 7.5
CVE-2026-37453
HIGH
MSI NBFoundation Service 2.0.2506.1201 - Insecure Permissions via MSI_SERVICE_2 Pipe
CVSS 7.5
CVE-2026-55180
MEDIUM
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVSS 6.5
CVE-2026-50017
MEDIUM
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVSS 6.5
CVE-2026-9153
MEDIUM
Arbitrary File Read in Rapid7 InsightConnect Sed Plugin
CVSS 6.5
CVE-2026-52815
MEDIUM
Gogs: Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-32315
MEDIUM
motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVSS 5.5
CVE-2026-47389
HIGH
Mastodon: SSRF protection bypass on older Ruby versions
CVSS 8.6
CVE-2026-53949
MEDIUM
Ghost Content API filter bypass reveals private fields
CVSS 5.3
CVE-2026-49269
HIGH
Apple M1 GPUs - Exposure of Sensitive Information via Stale Register File Data
CVSS 8.6
CVE-2026-56337
MEDIUM
Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2
CVSS 5.3
CVE-2026-56244
HIGH
Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key
CVSS 7.1
CVE-2026-9612
MEDIUM
WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs
CVSS 5.3
Details
Vulnerabilities
10,512
Exploit Likelihood
High