CWE-200 · 10,849 records
Exposure of sensitive information to an unauthorized actor
Why does it happen?
The extension requests broader permissions than its function needs and sends the data it collects out for purposes beyond its stated function.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
{ "permissions": ["tabs", "<all_urls>"], "background": { "service_worker": "analytics.js" }}Fixed
{ "permissions": ["activeTab"], "host_permissions": ["https://yildiz.example/*"]}How to prevent it
- 01Request only the permissions the function requires.
- 02Document collected data clearly and keep it to a minimum.
- 03Manage extensions with an allowlist in corporate browsers.
CVEs in this class
10,000 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
94Now | CVE-2024-24919Weaponized | Information disclosurecheckpoint · quantum spark firmware · CWE-200 | High8.6 | KEV | 100.0% | May 28, 2024 |
89Now | CVE-2021-41277Weaponized | GeoJSON URL validation can expose server files and environment variables to unauthorized usersmetabase · metabase · CWE-200 | High7.5 | KEV | 97.2% | Nov 17, 2021 |
86Now | CVE-2016-6415Weaponized | The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5cisco · ios · CWE-200 | High7.5 | KEV | 87.7% | Sep 18, 2016 |
85Now | CVE-2023-28432Weaponized | Minio Information Disclosure in Cluster Deploymentminio · minio · CWE-200 | High7.5 | KEV | 84.0% | Mar 22, 2023 |
84Now | CVE-2023-49103Weaponized | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.owncloud · graph api · CWE-200 | High7.5 | KEV | 78.4% | Nov 21, 2023 |
82Now | CVE-2020-3259Weaponized | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerabilitycisco · secure firewall threat defense · CWE-200 | High7.5 | KEV | 71.8% | May 6, 2020 |
79This week | CVE-2025-31125Weaponized | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryvitejs · vite · CWE-200 | High7.5 | KEV | 64.7% | Mar 31, 2025 |
76This week | CVE-2008-0655Weaponized | Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.adobe · acrobat · CWE-200 | High8.8 | KEV | 37.9% | Feb 7, 2008 |
70This week | CVE-2026-20133Weaponized | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affectcisco · catalyst sd-wan manager · CWE-200 | High7.5 | KEV | 31.8% | Feb 25, 2026 |
67This week | CVE-2021-27850Weaponized | Bypass of the fix for CVE-2019-0195apache · tapestry · CWE-200 | Critical9.8 | — | 93.5% | Apr 15, 2021 |
67This week | CVE-2016-2388Weaponized | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a craftedsap · netweaver application server java · CWE-200 | Medium5.3 | KEV | 52.2% | Feb 16, 2016 |
67This week | CVE-2015-5317Weaponized | The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name injenkins · jenkins · CWE-200 | High7.5 | KEV | 23.0% | Nov 25, 2015 |
66This week | CVE-2015-0310Weaponized | Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not padobe · flash player · CWE-200 | High7.8 | KEV | 15.1% | Jan 23, 2015 |
62This week | CVE-2018-1000600Proof of concept | A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java tjenkins · github · CWE-200 | High8.8 | — | 90.9% | Jun 26, 2018 |
62This week | CVE-2018-0127Proof of concept | A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allocisco · rv132w firmware · CWE-200 | Critical9.8 | — | 77.5% | Feb 8, 2018 |
62This week | CVE-2025-68686Weaponized | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,fortinet · fortios · CWE-200 | Medium5.9 | KEV | 29.6% | Feb 10, 2026 |
61This week | CVE-2025-11749Weaponized | AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalationtigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress · CWE-200 | Critical9.8 | — | 74.8% | Nov 5, 2025 |
61This week | CVE-2018-7251Proof of concept | An issue was discovered in config/error.php in Anchor 0.12.3.anchorcms · anchor · CWE-200 | Critical9.8 | — | 71.8% | Feb 19, 2018 |
59Plan | CVE-2022-20821Weaponized | Cisco IOS XR Software Health Check Open Port Vulnerabilitycisco · ios xr · CWE-200 | Medium6.5 | KEV | 11.5% | May 26, 2022 |
58Plan | CVE-2016-2183Proof of concept | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | High7.5 | — | 94.7% | Aug 31, 2016 |
58Plan | CVE-2016-10175Weaponized | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI.netgear · wnr2000v5 firmware · CWE-200 | Critical9.8 | — | 65.0% | Jan 30, 2017 |
58Plan | CVE-2017-11165Proof of concept | dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for ththermofisher · dt80 dex firmware · CWE-200 | Critical9.8 | — | 63.9% | Jul 12, 2017 |
57Plan | CVE-2011-3497Weaponized | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibmeasuresoft · scadapro · CWE-200 | Critical10.0 | — | 57.1% | Sep 16, 2011 |
56Plan | CVE-2017-16894Weaponized | In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct relaravel · laravel · CWE-200 | High7.5 | — | 86.9% | Nov 19, 2017 |
56Plan | CVE-2018-4993Weaponized | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO haadobe · acrobat dc · CWE-200 | High7.5 | — | 86.7% | Jul 9, 2018 |
- CVE-2024-2491994Now
Information disclosure
HighCVSS 8.6KEVWeaponizedEPSS 100%checkpoint · quantum spark firmwareMay 28, 2024
- CVE-2021-4127789Now
GeoJSON URL validation can expose server files and environment variables to unauthorized users
HighCVSS 7.5KEVWeaponizedEPSS 97%metabase · metabaseNov 17, 2021
- CVE-2016-641586Now
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5
HighCVSS 7.5KEVWeaponizedEPSS 88%cisco · iosSep 18, 2016
- CVE-2023-2843285Now
Minio Information Disclosure in Cluster Deployment
HighCVSS 7.5KEVWeaponizedEPSS 84%minio · minioMar 22, 2023
- CVE-2023-4910384Now
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.
HighCVSS 7.5KEVWeaponizedEPSS 78%owncloud · graph apiNov 21, 2023
- CVE-2020-325982Now
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 72%cisco · secure firewall threat defenseMay 6, 2020
- CVE-2025-3112579This week
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
HighCVSS 7.5KEVWeaponizedEPSS 65%vitejs · viteMar 31, 2025
- CVE-2008-065576This week
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
HighCVSS 8.8KEVWeaponizedEPSS 38%adobe · acrobatFeb 7, 2008
- CVE-2026-2013370This week
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affect
HighCVSS 7.5KEVWeaponizedEPSS 32%cisco · catalyst sd-wan managerFeb 25, 2026
- CVE-2021-2785067This week
Bypass of the fix for CVE-2019-0195
CriticalCVSS 9.8WeaponizedEPSS 93%apache · tapestryApr 15, 2021
- CVE-2016-238867This week
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted
MediumCVSS 5.3KEVWeaponizedEPSS 52%sap · netweaver application server javaFeb 16, 2016
- CVE-2015-531767This week
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name in
HighCVSS 7.5KEVWeaponizedEPSS 23%jenkins · jenkinsNov 25, 2015
- CVE-2015-031066This week
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not p
HighCVSS 7.8KEVWeaponizedEPSS 15%adobe · flash playerJan 23, 2015
- CVE-2018-100060062This week
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java t
HighCVSS 8.8Proof of conceptEPSS 91%jenkins · githubJun 26, 2018
- CVE-2018-012762This week
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allo
CriticalCVSS 9.8Proof of conceptEPSS 77%cisco · rv132w firmwareFeb 8, 2018
- CVE-2025-6868662This week
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,
MediumCVSS 5.9KEVWeaponizedEPSS 30%fortinet · fortiosFeb 10, 2026
- CVE-2025-1174961This week
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
CriticalCVSS 9.8WeaponizedEPSS 75%tigroumeow · ai engine – the chatbot, ai framework & mcp for wordpressNov 5, 2025
- CVE-2018-725161This week
An issue was discovered in config/error.php in Anchor 0.12.3.
CriticalCVSS 9.8Proof of conceptEPSS 72%anchorcms · anchorFeb 19, 2018
- CVE-2022-2082159Plan
Cisco IOS XR Software Health Check Open Port Vulnerability
MediumCVSS 6.5KEVWeaponizedEPSS 11%cisco · ios xrMay 26, 2022
- CVE-2016-218358Plan
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
HighCVSS 7.5Proof of conceptEPSS 95%redhat · jboss enterprise application platformAug 31, 2016
- CVE-2016-1017558Plan
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI.
CriticalCVSS 9.8WeaponizedEPSS 65%netgear · wnr2000v5 firmwareJan 30, 2017
- CVE-2017-1116558Plan
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for th
CriticalCVSS 9.8Proof of conceptEPSS 64%thermofisher · dt80 dex firmwareJul 12, 2017
- CVE-2011-349757Plan
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possib
CriticalCVSS 10.0WeaponizedEPSS 57%measuresoft · scadaproSep 16, 2011
- CVE-2017-1689456Plan
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct re
HighCVSS 7.5WeaponizedEPSS 87%laravel · laravelNov 19, 2017
- CVE-2018-499356Plan
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO ha
HighCVSS 7.5WeaponizedEPSS 87%adobe · acrobat dcJul 9, 2018