Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an
The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access deb
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Startin
WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remot
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauth
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to vers
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized acc
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize
Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an auth
An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information w
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iO
The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POS
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p
Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di
In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the applicatio
LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to expo
LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints
The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize
GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensiti
Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affec
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerabil
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker
PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Altho
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen
A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on si
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is e
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations b
Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories A
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET
An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker t
Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead t
Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker
Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of thi
This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may
In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the cod
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started