An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 t
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapsho
The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing a
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applica
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Information Exposure in all vers
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauth
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection
The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.
OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16.
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API key
The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Expos
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thun
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
The PDF Resume Parser plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all
The application discloses all used components, versions and license information to unauthenticated actors, giving attack
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app
The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers
A vulnerability was detected in birkir prime up to 0.4.0.beta.0. This issue affects some unknown processing of the file
A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql
A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affec
Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Pl
phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly e
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve sta
The WP Adminify plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Di
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur
The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in
The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin ur
A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of
A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown funct
A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an u
A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/public
A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/Download
A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-b
The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the publi
The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi
The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 v
The Web Accessibility by accessiBe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started