Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 19/154
5.3
CVE-2026-56456

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently

5.3
CVE-2026-13402

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem

5.3
CVE-2024-23568

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th

5.3
CVE-2026-58149

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i

5.3
CVE-2026-16201

A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file

5.3
CVE-2026-60156

Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily

5.3
CVE-2026-60237

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

5.3
CVE-2026-60260

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

5.3
CVE-2026-60283

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

5.3
CVE-2026-60394

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-

5.3
CVE-2026-60611

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The

5.3
CVE-2026-60888

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor

5.3
CVE-2026-61050

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface). Suppo

5.3
CVE-2026-62490

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

5.3
CVE-2026-61392

There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain

5.3
CVE-2026-14820

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log

5.3
CVE-2026-15012

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C

5.3
CVE-2026-16773

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In

5.3
CVE-2026-11351

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API e

5.3
CVE-2026-66489

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

5.3
CVE-2026-18059

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp

5.3
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR

5.3
CVE-2026-69153

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract

5.3
CVE-2026-18974

A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the

5.3
CVE-2026-14240

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub

5.3
CVE-2026-14314

The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel

5.3
CVE-2026-48078

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.3
CVE-2026-71433

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin

5.3
CVE-2026-19229

A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona

5.3
CVE-2026-19356

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/dat

5.3
CVE-2026-19357

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form

5.3
CVE-2026-19363

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handl

5.3
CVE-2026-19074

The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i

5.3
CVE-2026-72549

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers

5.3
CVE-2026-19073

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o

5.3
CVE-2026-66272

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vul

5.3
CVE-2026-68520

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py c

5.3
CVE-2026-70911

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

5.3
CVE-2026-70974

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

5.3
CVE-2026-71087

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

5.3
CVE-2026-18231

The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX ac

5.3
CVE-2026-18778

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, all

5.3
CVE-2026-76206

phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing unauthenticated attac

5.3
CVE-2026-53452

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.

5.3
CVE-2026-76390

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the

5.3
CVE-2026-16575

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict acc

5.3
CVE-2026-27463

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the logi

5.3
CVE-2026-53497

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without aut

5.3
CVE-2026-16612

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauth

5.3
CVE-2026-56380

AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthentica

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started