Skip to content
Noroxi

CWE-200 · 10,849 records

Exposure of sensitive information to an unauthorized actor

Why does it happen?

The extension requests broader permissions than its function needs and sends the data it collects out for purposes beyond its stated function.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

json
{  "permissions": ["tabs", "<all_urls>"],  "background": { "service_worker": "analytics.js" }}

Fixed

json
{  "permissions": ["activeTab"],  "host_permissions": ["https://yildiz.example/*"]}

How to prevent it

  1. 01Request only the permissions the function requires.
  2. 02Document collected data clearly and keep it to a minimum.
  3. 03Manage extensions with an allowlist in corporate browsers.

CVEs in this class

10,000 records

  • Information disclosure

    HighCVSS 8.6KEVWeaponizedEPSS 100%

    checkpoint · quantum spark firmwareMay 28, 2024

  • GeoJSON URL validation can expose server files and environment variables to unauthorized users

    HighCVSS 7.5KEVWeaponizedEPSS 97%

    metabase · metabaseNov 17, 2021

  • The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5

    HighCVSS 7.5KEVWeaponizedEPSS 88%

    cisco · iosSep 18, 2016

  • Minio Information Disclosure in Cluster Deployment

    HighCVSS 7.5KEVWeaponizedEPSS 84%

    minio · minioMar 22, 2023

  • An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.

    HighCVSS 7.5KEVWeaponizedEPSS 78%

    owncloud · graph apiNov 21, 2023

  • Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 72%

    cisco · secure firewall threat defenseMay 6, 2020

  • CVE-2025-31125
    79This week

    Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query

    HighCVSS 7.5KEVWeaponizedEPSS 65%

    vitejs · viteMar 31, 2025

  • CVE-2008-0655
    76This week

    Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

    HighCVSS 8.8KEVWeaponizedEPSS 38%

    adobe · acrobatFeb 7, 2008

  • CVE-2026-20133
    70This week

    A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affect

    HighCVSS 7.5KEVWeaponizedEPSS 32%

    cisco · catalyst sd-wan managerFeb 25, 2026

  • CVE-2021-27850
    67This week

    Bypass of the fix for CVE-2019-0195

    CriticalCVSS 9.8WeaponizedEPSS 93%

    apache · tapestryApr 15, 2021

  • CVE-2016-2388
    67This week

    The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted

    MediumCVSS 5.3KEVWeaponizedEPSS 52%

    sap · netweaver application server javaFeb 16, 2016

  • CVE-2015-5317
    67This week

    The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name in

    HighCVSS 7.5KEVWeaponizedEPSS 23%

    jenkins · jenkinsNov 25, 2015

  • CVE-2015-0310
    66This week

    Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not p

    HighCVSS 7.8KEVWeaponizedEPSS 15%

    adobe · flash playerJan 23, 2015

  • CVE-2018-1000600
    62This week

    A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java t

    HighCVSS 8.8Proof of conceptEPSS 91%

    jenkins · githubJun 26, 2018

  • CVE-2018-0127
    62This week

    A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allo

    CriticalCVSS 9.8Proof of conceptEPSS 77%

    cisco · rv132w firmwareFeb 8, 2018

  • CVE-2025-68686
    62This week

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,

    MediumCVSS 5.9KEVWeaponizedEPSS 30%

    fortinet · fortiosFeb 10, 2026

  • CVE-2025-11749
    61This week

    AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

    CriticalCVSS 9.8WeaponizedEPSS 75%

    tigroumeow · ai engine – the chatbot, ai framework & mcp for wordpressNov 5, 2025

  • CVE-2018-7251
    61This week

    An issue was discovered in config/error.php in Anchor 0.12.3.

    CriticalCVSS 9.8Proof of conceptEPSS 72%

    anchorcms · anchorFeb 19, 2018

  • Cisco IOS XR Software Health Check Open Port Vulnerability

    MediumCVSS 6.5KEVWeaponizedEPSS 11%

    cisco · ios xrMay 26, 2022

  • The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr

    HighCVSS 7.5Proof of conceptEPSS 95%

    redhat · jboss enterprise application platformAug 31, 2016

  • The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI.

    CriticalCVSS 9.8WeaponizedEPSS 65%

    netgear · wnr2000v5 firmwareJan 30, 2017

  • dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for th

    CriticalCVSS 9.8Proof of conceptEPSS 64%

    thermofisher · dt80 dex firmwareJul 12, 2017

  • service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possib

    CriticalCVSS 10.0WeaponizedEPSS 57%

    measuresoft · scadaproSep 16, 2011

  • In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct re

    HighCVSS 7.5WeaponizedEPSS 87%

    laravel · laravelNov 19, 2017

  • Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO ha

    HighCVSS 7.5WeaponizedEPSS 87%

    adobe · acrobat dcJul 9, 2018

All vulnerability classes