Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 13/154
6.3
CVE-2026-44408

There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an

6.3
CVE-2026-15044

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific s

6.3
CVE-2026-45737

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Ar

6.3
CVE-2026-61117

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.3
CVE-2026-61216

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that ar

6.3
CVE-2026-61266

Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Org

6.3
CVE-2026-61279

Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Proposals). Supported versions tha

6.3
CVE-2026-61294

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchro

6.3
CVE-2026-61304

Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Suppo

6.3
CVE-2026-62453

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported ve

6.3
CVE-2026-62519

Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Succession plan). Suppor

6.3
CVE-2026-62524

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported v

6.3
CVE-2026-62525

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Quality Workbench HTML system). Supp

6.3
CVE-2026-62527

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supp

6.3
CVE-2026-62528

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Suppor

6.2
CVE-2026-20821

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attac

6.2
CVE-2025-68959

Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner

6.2
CVE-2026-0005

In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim

6.2
CVE-2026-29066

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.

6.2
CVE-2025-71280

XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu

6.2
CVE-2026-49807

Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclos

6.2
CVE-2026-57095

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate

6.2
CVE-2026-17966

Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain

6.2
CVE-2026-54785

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti

6.2
CVE-2026-71293

Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f

6.2
CVE-2026-72744

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the

6.2
CVE-2026-73047

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view

6.2
CVE-2026-49301

Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect

6.2
CVE-2026-49302

Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerabili

6.2
CVE-2026-49307

Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability m

6.1
CVE-2026-31262

Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai

6.1
CVE-2026-54264

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-50169

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-50184

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other

6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca

6.1
CVE-2026-50019

yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downlo

6.1
CVE-2026-46406

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha

6.0
CVE-2026-44276

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth

5.9
CVE-2026-24916

Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability

5.9
CVE-2025-68686 KEV

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS

5.9
CVE-2026-26014

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1

5.9
CVE-2026-1867

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to reg

5.9
CVE-2025-67805

A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat

5.9
CVE-2026-14062

Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convin

5.9
CVE-2026-60266

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

5.9
CVE-2026-60349

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supporte

5.9
CVE-2026-60610

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The

5.9
CVE-2026-61103

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The

5.9
CVE-2026-58432

Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti

5.9
CVE-2026-69224

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under diff

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started