DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In version
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was inval
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensit
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated us
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension manageme
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and
umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. Th
Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre da
APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized
An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret k
In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability
An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26
DVP-12SE11T - Authentication Bypass via Partial Password Disclosure
A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitter
A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VA
Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users o
Information disclosure may occur due to improper permission and access controls to Video Analytics engine.
An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contai
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storag
pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. In
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533.
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to
Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to di
Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained
KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensi
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. When you send a request with the Authori
An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via craft
Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a devic
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa
AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the us
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where
An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function
In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a targ
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started