CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,512 vulnerabilities with CWE-200
CVE-2026-56218 MEDIUM
Capgo - EXIF Metadata Exposure via Image Upload
CVSS 5.3
CVE-2026-56214 HIGH
Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC
CVSS 7.5
CVE-2026-56079 MEDIUM
Capgo - Cross-Tenant Authorization Bypass via PostgREST Webhook Access
CVSS 6.5
CVE-2026-49336 MEDIUM
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
CVE-2026-49288 MEDIUM
Statamic CMS < 5.73.23 and 6.x < 6.20.0 - Control Panel Resource Disclosure
CVSS 4.3
CVE-2026-12620 MEDIUM
Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
CVSS 6.5
CVE-2026-47633 HIGH
Microsoft Cost Management Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-12111 MEDIUM
Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter
CVSS 4.3
CVE-2026-12120 MEDIUM
FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' Parameter
CVSS 5.3
CVE-2026-11357 MEDIUM
Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization
CVSS 4.3
CVE-2026-50200 HIGH
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVSS 7.5
CVE-2026-47340 MEDIUM
Apache DolphinScheduler < 3.4.2 - Unauthorized Alert Instance Access
CVSS 6.5
CVE-2026-46977 LOW
Oracle VM VirtualBox 7.2.8 - Authenticated Unauthorized Data Read via VMSVGA Device
CVSS 3.2
CVE-2026-46912 CRITICAL
JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2 - Unauthenticated Unauthorized Data Access via Web Runtime Security
CVSS 9.3
CVE-2026-46910 CRITICAL
Oracle Corporation JD Edwards EnterpriseOne Tools < 9.2.26.2 - Denial of Service
CVSS 9.1
CVE-2026-46874 LOW
Oracle VM VirtualBox 7.2.8 - Authenticated Unauthorized Data Read
CVSS 3.2
CVE-2026-46816 LOW
Oracle VM VirtualBox 7.2.8 - Authenticated Unauthorized Data Read in VMSVGA Device
CVSS 3.2
CVE-2026-46815 LOW
Oracle VM VirtualBox 7.2.8 - Authenticated Unauthorized Data Read via VMSVGA Device
CVSS 3.2
CVE-2026-46790 MEDIUM
Oracle WebCenter Content 14.1.2.0.0 - Unauthenticated Unauthorized Data Read via HTTP
CVSS 5.3
CVE-2026-12117 MEDIUM
Devolutions Server < 2026.2.5 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 4.3
CVE-2026-12320 MEDIUM
Mozilla Firefox - Information Disclosure in the Password Manager Component
CVSS 4.3
CVE-2026-12311 MEDIUM
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 4.7
CVE-2026-50870 HIGH
whoogle-search 1.2.3 - Information Disclosure via Configuration Endpoint
CVSS 7.5
CVE-2026-39007 HIGH
Observeinc Observe v.2026-01-28 and before - Information Disclosure via CSV Log Export
CVSS 7.5
CVE-2026-8385 MEDIUM
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
CVSS 5.3
Details
Vulnerabilities 10,512
Exploit Likelihood High