The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON seri
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication ru
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, al
Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compro
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJA
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal s
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in a
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowi
A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the compo
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging so
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was
wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expo
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) co
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l
The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p
Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*pa
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while comm
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password
HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes
The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, ann
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi
An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive i
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker w
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resou
Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se
The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of
GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system
A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.j
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started