The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensit
An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensi
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information E
An attacker may modify the URL to discover sensitive information about the target network.
The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi
An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselecta
An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function
An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.
An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Informati
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu
An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Acade
Buffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web U
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the
An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function
Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `
Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could l
Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.
Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex
The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to dis
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that
An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 a
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—i
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerabili
The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port
An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Des
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of conf
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the D
Discourse is an open-source discussion platform. The visibility of posts typed `whisper` is controlled via the `whispers
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sens
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token componen
A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote ser
Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html end
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker
KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers t
Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used
Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the data
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started