CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,505 vulnerabilities with CWE-200
CVE-2026-60264 CRITICAL
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Remote Code Execution via HTTP/2
CVSS 9.8
CVE-2026-60260 MEDIUM
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0 - Unauthenticated Information Disclosure via HTTP
CVSS 5.3
CVE-2026-60237 MEDIUM
Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 - Unauthenticated Information Disclosure via TCP
CVSS 5.3
CVE-2026-60176 HIGH
Oracle Payments < 12.2.15 - Denial of Service
CVSS 7.1
CVE-2026-60167 HIGH
Oracle Hospitality Simphony 19.8-19.8.5, 19.9-19.9.3, 19.10 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2026-60160 LOW
Oracle VM VirtualBox 7.2.12 - Unauthorized Data Read via Core Component
CVSS 3.2
CVE-2026-60156 MEDIUM
Oracle APEX 24.1, 24.2, and 26.1 - Unauthenticated Information Disclosure via HTTP
CVSS 5.3
CVE-2026-47247 HIGH
libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
CVSS 7.5
CVE-2026-47043 LOW
Oracle VM VirtualBox 7.2.12 - Unauthorized Data Read via Local Privilege Escalation
CVSS 3.2
CVE-2026-47016 LOW
Siebel CRM Integration 17.0-26.4 - Unauthorized Data Access via Physical Access to Event Publish and Subscribe Component
CVSS 1.9
CVE-2026-47009 MEDIUM
Oracle Agile PLM 9.3.6 - Unauthenticated Unauthorized Data Access via Folders, Files & Attachments Component
CVSS 6.5
CVE-2026-52474 HIGH
AiFlowy <= 2.1.2 - Sensitive Information Exposure via JobUtil.java
CVSS 7.5
CVE-2026-56579 LOW
HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.
CVSS 3.1
CVE-2026-56578 LOW
HCL MyCloud was affected by Server Version Disclosure
CVSS 2.2
CVE-2026-21579 HIGH
Atlassian Confluence Data Center - Information Disclosure
CVE-2026-47395 MEDIUM
PraisonAI < 4.6.40 CLI @url Mentions - Loopback Data Exposure
CVSS 5.5
CVE-2026-47394 HIGH
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-56584 LOW
HCL IEM was affected with the Information disclosure nginx server
CVSS 3.7
CVE-2026-16405 HIGH
Information disclosure in the Networking: WebSockets component
CVSS 7.5
CVE-2026-16400 HIGH
Information disclosure in the DOM: Security component
CVSS 7.5
CVE-2026-16398 HIGH
Mozilla Firefox - Site Isolation Issue in the Graphics Component
CVSS 7.5
CVE-2026-16391 HIGH
Information disclosure in the Storage: IndexedDB component
CVSS 7.5
CVE-2026-16387 CRITICAL
Mozilla Firefox - Site Isolation Issue in the Networking Component
CVSS 9.8
CVE-2026-16374 HIGH
Mozilla Firefox - Information Disclosure in the Framework Component in DevTools
CVSS 7.5
CVE-2026-16373 HIGH
Information disclosure in the Privacy component in Firefox for Android
CVSS 7.5
Details
Vulnerabilities 10,505
Exploit Likelihood High