CWE-200Class10 in KEV

Exposure of Sensitive Information to an Unauthorized Actor

Draft in the CWE catalog · 3,744 CVEs mapped

3,744
CVEs mapped
10
In KEV
5.5
Median CVSS
What it is

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Recent examples
5.3cvss
CVE-2026-86217

code-projects Hotel and Tourism Reservation in PHP Database Backup hotel_db%20(1).sql information disclosure

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

MEDIUMno explanation yet
epss
5.3cvss
CVE-2026-86179

code-projects Daily Expense Manager Database Backup exp_ak.sql information disclosure

A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.

MEDIUMno explanation yet
epss
9.1cvss
CVE-2026-86190

CVE-2026-86190 - CRITICAL Severity Vulnerability

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.

CRITICALno explanation yet
epss
The record
Technical detail
CWE ID
CWE-200
Abstraction
Class
Structure
Simple
Status
Draft
References (3)