HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file
Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface). Suppo
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).
There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain
The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API e
Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the
The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin
A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona
A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/dat
A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handl
The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vul
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py c
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX ac
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, all
phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing unauthenticated attac
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict acc
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the logi
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without aut
The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauth
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthentica
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started