CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,504 vulnerabilities with CWE-200
CVE-2026-43782 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unprotected User Data Exposure via App Sandbox Bypass
CVSS 5.5
CVE-2026-43759 MEDIUM
macOS and watchOS < 26.6 - Unprotected User Data Exposure via Authorization State Management Flaw
CVSS 5.5
CVE-2026-43758 MEDIUM
Apple macOS and watchOS - Sensitive User Data Exposure
CVSS 5.5
CVE-2026-43756 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Sensitive User Data Exposure
CVSS 5.5
CVE-2026-43754 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unprotected Kernel State Exposure via Sensitive Information Redaction Issue
CVSS 5.5
CVE-2026-43730 CRITICAL
Apple Ios And iPadOS - Denial of Service
CVSS 9.8
CVE-2026-20672 MEDIUM
Apple macOS - Information Disclosure
CVSS 5.5
CVE-2026-66018 MEDIUM
JFrog Artifactory build environment properties exposure
CVSS 6.5
CVE-2026-42017 HIGH
Privilege escalation via JFrog Worker event token exposure
CVSS 8.8
CVE-2026-17612 MEDIUM
Honeywell S35 Series 3M/5M/8M/PinHole Cameras - Audit Log Exposure Through Unauthorized Access
CVE-2026-45623 HIGH
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
CVSS 7.5
CVE-2026-14820 MEDIUM
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
CVSS 5.3
CVE-2026-17457 MEDIUM
mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure
CVSS 4.3
CVE-2026-55729 HIGH
Loytec LWEB802: Exposure of Sensitive Information in browser localStorage
CVE-2026-17048 MEDIUM
Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api
CVSS 5.5
CVE-2026-49159 MEDIUM
Microsoft Graph Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-47743 HIGH
Shopper: Multiple data integrity and disclosure issues in admin Livewire components
CVSS 8.7
CVE-2026-65760 CRITICAL
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1
CVE-2026-65758 HIGH
Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2
CVE-2026-65430 HIGH
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension
CVSS 7.5
CVE-2026-64874 CRITICAL
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension
CVSS 9.8
CVE-2026-60371 HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via Physical Network Access
CVSS 8.0
CVE-2026-44276 MEDIUM
Dell PowerProtect Data Manager < 20.2.0.0 or later - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.0
CVE-2026-61392 MEDIUM
Hikvision DS-2CD Series - Information Disclosure
CVSS 5.3
CVE-2026-62567 HIGH
Oracle HRMS (UK) 12.2.3-12.2.15 - Authenticated Unauthorized Data Access via UK Payroll Component
CVSS 7.7
Details
Vulnerabilities 10,504
Exploit Likelihood High