Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled Gra
A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed infor
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp
A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome.
Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende
Information leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the confi
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The applicat
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite"
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.63
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post E
A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of
An issue that could allow a user with access to a credential to view sensitive fields through an API response has been r
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t
Tanium addressed an information disclosure vulnerability in Threat Response.
Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (m
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Suppo
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of
Webhook Authorization Header Returned in Plaintext via API
A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to t
The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allo
HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Expose
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP ad
Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre
A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/m
A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functio
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker t
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities
Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the com
BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the m
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica
Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supp
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started