CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,512 vulnerabilities with CWE-200
CVE-2026-9183 MEDIUM
24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script Localization
CVSS 4.3
CVE-2026-47379 MEDIUM
NocoDB: Plaintext Password Comparison in Shared Views
CVE-2026-54317 HIGH
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
CVSS 7.6
CVE-2026-54316 CRITICAL
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
CVSS 9.1
CVE-2026-55450 CRITICAL
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVSS 9.3
CVE-2026-55447 CRITICAL
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVSS 9.6
CVE-2026-54305 CRITICAL
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVSS 9.9
CVE-2026-54304 HIGH
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVSS 7.7
CVE-2026-50019 MEDIUM
yt-dlp: File Downloader cookie leak with curl
CVSS 6.1
CVE-2026-27604 CRITICAL
FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions
CVE-2026-56322 HIGH
Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter
CVSS 7.5
CVE-2026-53923 HIGH
vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow
CVSS 7.5
CVE-2026-56323 HIGH
Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self
CVSS 7.5
CVE-2026-54276 MEDIUM
AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
CVSS 6.1
CVE-2026-53571 HIGH
Vite: `server.fs.deny` bypass on Windows alternate paths
CVSS 7.5
CVE-2026-50184 MEDIUM
Angular: Request Credential & Cache Policy Stripping in Angular Service Worker
CVSS 6.1
CVE-2026-50169 MEDIUM
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
CVSS 6.1
CVE-2026-49356 LOW
Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core
CVSS 3.2
CVE-2026-54264 MEDIUM
Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
CVSS 6.1
CVE-2026-7167 MEDIUM
Gaudire Assassin Game Email Validation - Fraudulent Account Creation
CVE-2026-7166 CRITICAL
Gaudire Assassin Game API - Sensitive Data Exposure
CVE-2026-56242 HIGH
Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPC
CVSS 7.5
CVE-2026-56282 MEDIUM
Capgo - Information Disclosure via Unauthenticated /replication Endpoint
CVSS 5.3
CVE-2026-56267 MEDIUM
Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint
CVE-2026-56235 MEDIUM
Capgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions
CVSS 5.3
Details
Vulnerabilities 10,512
Exploit Likelihood High