Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 3/154
8.1
CVE-2026-41323

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc

8.1
CVE-2026-60558

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

8.1
CVE-2026-60844

Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Su

8.1
CVE-2026-60415

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

8.1
CVE-2026-70943

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

8.1
CVE-2026-17060

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a

8.0
CVE-2026-0411

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected

8.0
CVE-2026-60371

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third

8.0
CVE-2026-48080

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

7.9
CVE-2025-65104

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect

7.9
CVE-2026-41520

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.

7.8
CVE-2026-50697

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized

7.8
CVE-2026-60413

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th

7.8
CVE-2026-60414

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th

7.7
CVE-2025-61917

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe

7.7
CVE-2025-48635

In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic er

7.7
CVE-2026-34242

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f

7.7
CVE-2026-36355

The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo

7.7
CVE-2026-44738

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.page

7.7
CVE-2026-42283

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI se

7.7
CVE-2026-46427

Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/dataso

7.7
CVE-2026-54304

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with pe

7.7
CVE-2026-49984

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba

7.7
CVE-2026-59216

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call de

7.7
CVE-2026-49853

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-cop

7.7
CVE-2026-60440

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp

7.7
CVE-2026-60548

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Su

7.7
CVE-2026-60923

Vulnerability in the Oracle Capacity product of Oracle E-Business Suite (component: Internal Operations). Supported ver

7.7
CVE-2026-61014

Vulnerability in the Oracle Inventory Management product of Oracle E-Business Suite (component: Internal Operations). S

7.7
CVE-2026-61125

Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench)

7.7
CVE-2026-62560

Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supporte

7.7
CVE-2026-62567

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th

7.7
CVE-2026-72670

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a confi

7.7
CVE-2026-60969

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

7.7
CVE-2026-70942

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

7.7
CVE-2026-73137

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A te

7.7
CVE-2026-34948

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are pr

7.7
CVE-2026-77017

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine t

7.7
CVE-2026-81679

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST AP

7.6
CVE-2025-70963

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived

7.6
CVE-2026-2476

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with

7.6
CVE-2026-6347

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie

7.6
CVE-2026-54317

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the

7.6
CVE-2026-60886

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor

7.6
CVE-2026-62518

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).

7.6
CVE-2026-48766

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr

7.6
CVE-2026-48767

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain

7.6
CVE-2026-69189

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLH

7.5
CVE-2025-37165

A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration d

7.5
CVE-2026-22240

The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unau

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started