Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 12/154
6.5
CVE-2026-61918

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-61921

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-61924

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-65769

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to

6.5
CVE-2026-66301

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized

6.5
CVE-2026-12976

The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a

6.5
CVE-2026-13168

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users

6.5
CVE-2026-18943

The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow

6.5
CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a

6.5
CVE-2026-73604

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoi

6.5
CVE-2026-57897

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

6.5
CVE-2026-58442

Repository migration SSRF via multi-answer DNS allow-list bypass

6.5
CVE-2026-16541

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some o

6.5
CVE-2026-19613

The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeate

6.5
CVE-2026-64778

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS

6.5
CVE-2026-74945

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

6.5
CVE-2026-74948

Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef

6.5
CVE-2026-70975

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.5
CVE-2026-53959

4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to

6.5
CVE-2026-61842

Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to ret

6.5
CVE-2026-76366

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (

6.5
CVE-2026-53586

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

6.5
CVE-2026-16964

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due

6.5
CVE-2026-67448

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin mid

6.5
CVE-2026-72698

Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing

6.5
CVE-2026-78893

Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information

6.5
CVE-2026-78960

Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin

6.5
CVE-2026-78981

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obt

6.5
CVE-2026-79018

Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i

6.5
CVE-2026-79024

Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

6.5
CVE-2026-79075

Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi

6.5
CVE-2026-79124

Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sens

6.5
CVE-2026-79125

Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information

6.5
CVE-2026-79207

Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensi

6.5
CVE-2026-79246

Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i

6.5
CVE-2026-79271

Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

6.5
CVE-2026-79291

Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informatio

6.5
CVE-2026-79293

Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info

6.5
CVE-2026-78146

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named i

6.5
CVE-2026-48786

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endp

6.5
CVE-2026-46370

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels

6.5
CVE-2026-46371

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M

6.5
CVE-2026-81101

The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i

6.5
CVE-2026-61802

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

6.5
CVE-2026-82306

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi

6.4
CVE-2026-28682

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th

6.4
CVE-2026-60620

Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Manage

6.4
CVE-2026-60864

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).

6.3
CVE-2026-31370

Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect serv

6.3
CVE-2026-41610

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started