There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an
A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific s
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Ar
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that ar
Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Org
Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Proposals). Supported versions tha
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchro
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Suppor
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported v
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supp
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supp
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Suppor
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attac
Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclos
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti
Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the
siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view
Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect
Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerabili
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability m
Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca
yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downlo
Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth
Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1
The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to reg
A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat
Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convin
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supporte
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under diff
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started