Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoi
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Repository migration SSRF via multi-answer DNS allow-list bypass
The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some o
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeate
The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to ret
In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due
Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin mid
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing
Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information
Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin
Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obt
Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i
Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi
Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sens
Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information
Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensi
Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i
Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering
Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informatio
Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info
The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named i
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endp
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M
The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th
Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Manage
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).
Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect serv
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started