HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers
Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/user/User.
The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable
Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing add
A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid
The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una
The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the Pay
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.
Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to ve
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerabil
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with m
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read API
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and downl
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces
A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling
authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rus
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access co
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system v
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` functio
A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Ser
A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and A
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch
Backend users with file download permissions were able to download files from the fallback storage of the file abstracti
Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8
An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs du
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev
Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoin
Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p
The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vuln
Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 a
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff ac
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged st
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started