Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.
A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Chang
ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In
A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of
A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_ap
wpForo Forum 2.4.14 contains an information disclosure vulnerability that allows unauthenticated users to retrieve priva
The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handle
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d
Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attac
Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul
Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is
OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to en
WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the appl
The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin f
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affect
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sen
WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t
A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the fun
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts)
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be
A vulnerability was identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The impacted element is an unknown funct
A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/
A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint s
The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural f
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents end
OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by
A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea.
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri
The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some P
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started