Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vul
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne
Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized att
The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `shoul
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan
The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references.
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The su
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Communication).
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that
Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementat
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are aff
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supp
Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (component: Payroll). Supported versions that
Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Ser
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose
Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor
Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent
Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain p
Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit
The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi
In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datado
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/
An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started