Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to
Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a sound
@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname,
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may le
Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is in
Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submission
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0
Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all pla
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code
axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hard
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti
Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to
Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe
Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows w
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mc
Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/u
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`inte
Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof`
Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlle
RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Locati
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Althoug
Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende
Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integrati
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-priv
WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoint
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with acc
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docus
An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by de
Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows at
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 thro
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an er
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, ma
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable Open
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access pr
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.
This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started