CWE-200

High likelihood

Exposure of Sensitive Information to an Unauthorized Actor

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

10,505 vulnerabilities with CWE-200
CVE-2026-16354 HIGH
Information disclosure in the Graphics: ImageLib component
CVSS 7.5
CVE-2026-65009 MEDIUM
OpenRemote before 1.26.2 Information Disclosure via Syslog REST API
CVSS 4.3
CVE-2026-44231 CRITICAL
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
CVSS 9.1
CVE-2026-60031 MEDIUM
Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1
CVE-2026-51027 CRITICAL
FileThingie 2.5.7 - Unauthenticated Information Disclosure via ft2.php
CVSS 9.9
CVE-2026-46410 HIGH
FileBrowser Quantum: unauthenticated user share share info
CVE-2026-63746 MEDIUM
SurrealDB before 3.1.0 Permission Bypass via Graph Traversal
CVSS 6.5
CVE-2026-8825 MEDIUM
Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
CVSS 4.9
CVE-2026-16201 MEDIUM
zevorn rt-claw http_request net.c claw_net_post information disclosure
CVSS 5.3
CVE-2026-44979 MEDIUM
@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirects
CVE-2026-52203 HIGH
MCMS 6.1.1 - Unauthenticated Information Disclosure via Source Parameter
CVSS 7.5
CVE-2026-48009 MEDIUM
Shopware: Admin Account Takeover via User Recovery Hash Exposure
CVSS 6.8
CVE-2026-49211 HIGH
Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
CVSS 7.5
CVE-2026-16108 MEDIUM
Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2
CVSS 4.3
CVE-2026-58149 MEDIUM
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
CVSS 5.3
CVE-2026-9656 MEDIUM
HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script
CVSS 4.3
CVE-2026-13402 MEDIUM
Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
CVSS 5.3
CVE-2026-14503 MEDIUM
pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read
CVSS 6.5
CVE-2026-55406 MEDIUM
Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
CVE-2026-47751 MEDIUM
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
CVE-2026-57205 MEDIUM
SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints
CVSS 4.3
CVE-2026-53598 HIGH
Prompty: Arbitrary File Read via ${file:path} Reference Expansion
CVSS 7.5
CVE-2026-56456 MEDIUM
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability.
CVSS 5.3
CVE-2026-35145 LOW
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.
CVSS 3.1
CVE-2026-35143 LOW
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.
CVSS 3.0
Details
Vulnerabilities 10,505
Exploit Likelihood High