When trying to keep information confidential, an attacker can often infer some of the information by using statistics.
Volume of CVEs assigned to CWE-202 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69200HIGH phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/ | Dec 29, 2025 | 7.5 | 38 | NO | YES |
CVE-2025-25205HIGH Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticat | Feb 12, 2025 | 8.2 | 34 | NO | YES |
CVE-2025-68456CRITICAL Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations | Jan 5, 2026 | 9.1 | 32 | NO | NO |
CVE-2025-59352CRITICAL Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recipi | Sep 17, 2025 | 9.8 | 29 | NO | NO |
CVE-2021-32743HIGH Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11 | Jul 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2026-30778HIGH The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
This issue affects Apache SkyWalking: from 9.7.0 through 10.3. | Apr 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-40245HIGH Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disclosure vulnerability in the UDR | Apr 16, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33530MEDIUM InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive | Mar 26, 2026 | 6.5 | 24 | NO | NO |
CVE-2022-41623HIGH Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress. | Oct 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2026-42797MEDIUM Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL | May 25, 2026 | 4.9 | 23 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.