CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,504 vulnerabilities with CWE-200
CVE-2026-63240 MEDIUM
Three Learning Koollab Lms < 5.3.2 - Information Disclosure
CVSS 4.3
CVE-2026-11351 MEDIUM
ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure
CVSS 5.3
CVE-2026-54659 MEDIUM
Pagy I18n locale option is not validated before being used in a file path
CVE-2026-55403 LOW
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
CVSS 3.7
CVE-2026-55390 HIGH
datamodel-code-generator 0.59.0-0.62.0 - XSD Path Traversal File Read
CVSS 7.5
CVE-2026-55389 HIGH
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
CVSS 7.5
CVE-2026-54605 HIGH
OAuth: Cross-origin token-request redirects can expose signed request metadata
CVSS 7.2
CVE-2026-54603 HIGH
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
CVSS 8.6
CVE-2026-8058 MEDIUM
This Power System update is being released to address a sensitive information disclosure
CVSS 4.5
CVE-2026-65881 HIGH
Joomdle < 3.1.1 - Insecure Defaults Allow CMS Account Access
CVSS 7.5
CVE-2026-18038 MEDIUM
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
CVSS 4.3
CVE-2026-16773 MEDIUM
WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action
CVSS 5.3
CVE-2026-15012 MEDIUM
Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy
CVSS 5.3
CVE-2026-51078 HIGH
DedeCMS 5.7.118 - Unauthenticated Information Disclosure via file_manage_control.php str Parameter
CVSS 7.5
CVE-2026-64755 MEDIUM
Apple Ios And iPadOS < 26.6 - Denial of Service
CVSS 5.5
CVE-2026-64744 MEDIUM
Apple macOS - Information Disclosure
CVSS 5.5
CVE-2026-64741 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-64734 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-64733 CRITICAL
Apple Ios And iPadOS - Denial of Service
CVSS 9.8
CVE-2026-64710 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unprotected User Data Exposure via Privacy Issue
CVSS 5.5
CVE-2026-64709 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-43801 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-43800 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-43797 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-43796 MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
Details
Vulnerabilities 10,504
Exploit Likelihood High