A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a
Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Infor
Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local a
phpgt/Dom provides access to modern DOM APIs. Versions of phpgt/Dom prior to 4.1.8 expose the GITHUB_TOKEN in the Dom wo
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthen
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, att
The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKi
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthK
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that
Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scann
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-
Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missi
The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versi
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document
Windows Themes Spoofing Vulnerability
Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtai
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An insecure default `Access-C
woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF inv
A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unau
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when proce
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_
A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, w
Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE)
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple
GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debu
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPa
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p
Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and
Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Ma
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator en
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an
cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.
Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules define
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downl
A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started