IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network vi
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain pl
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exac
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of t
Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such
An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks w
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge
An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not bei
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The i
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFil
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service.
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible
Cryptocat has an Unspecified Chat Participant User List Disclosure
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the H
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unautho
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accid
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of i
SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the under
SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Applica
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The Applica
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker
In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in
An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC20
Karotz API 12.07.19.00: Session Token Information Disclosure
IBM Watson Studio Local 1.2.3 could disclose sensitive information over the network that an attacked could use in furthe
An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root
IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the managemen
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn th
IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in t
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of
Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versi
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started