There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that m
Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informa
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are a
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket
An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible f
An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which a
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne
An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitiv
Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts return
NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to l
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a ses
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to d
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, ma
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.4, macOS Ta
This issue was addressed with improved data protection. This issue is fixed in macOS Tahoe 26.3. An app may be able to a
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Tahoe 26.3.
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5
In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This coul
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows
The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows s
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacke
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior,
This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.
Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI ru
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura
Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an a
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started