wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualifi
A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote atta
IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by enter
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login ont
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information t
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive info
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This infor
IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosur
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via
IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing
An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. When a specific URL
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive at
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosur
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosur
A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) coul
Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/aut
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attac
IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email addres
Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 20
The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array fo
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) add
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymou
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], w
The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUpl
In Moodle 3.2.x, global search displays user names for unauthenticated users.
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by t
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or n
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "SafariViewContro
Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V
Huawei eSpace IAD V300R002C01SPC100 and earlier versions have an information leak vulnerability; an attacker can check a
Huawei PC client software HiSuite 4.0.5.300_OVE has an information leak vulnerability; an attacker who can log in to the
NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind
An exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series
An exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless
An exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wi
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidde
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext i
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started