Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 34/154
6.2
CVE-2025-10536

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.

6.2
CVE-2025-58278

Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affec

6.2
CVE-2025-58305

Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m

6.2
CVE-2025-66304

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section

6.1
CVE-2020-13481

Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other s

6.1
CVE-2025-49177

A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length

6.1
CVE-2025-22227

In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to hap

6.1
CVE-2025-8887

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho

6.0
CVE-2025-4426

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad

5.9
CVE-2025-21242

Windows Kerberos Information Disclosure Vulnerability

5.9
CVE-2024-13623

The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up

5.9
CVE-2024-13641

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature

5.9
CVE-2024-13609

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive In

5.9
CVE-2024-13638

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio

5.9
CVE-2024-13640

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure

5.9
CVE-2025-30218

Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the

5.9
CVE-2025-4222

The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc

5.9
CVE-2025-49143

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by

5.9
CVE-2025-49150

Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enab

5.9
CVE-2025-52473

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Mult

5.9
CVE-2025-50862

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data e

5.9
CVE-2025-10744

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu

5.9
CVE-2025-61589

Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows

5.9
CVE-2025-13439

The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all

5.8
CVE-2025-21626

GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anony

5.8
CVE-2025-26485

A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts

5.8
CVE-2025-46813

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd

5.8
CVE-2025-61780

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclos

5.8
CVE-2025-53047

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are

5.7
CVE-2025-2228

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne

5.7
CVE-2025-20226

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107

5.7
CVE-2025-20232

In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2

5.7
CVE-2025-24270

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6

5.7
CVE-2024-11994

APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na

5.7
CVE-2025-20624

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge

5.7
CVE-2025-25209

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those

5.7
CVE-2024-58257

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com

5.7
CVE-2025-26709

There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface

5.7
CVE-2025-26711

There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interfa

5.6
CVE-2003-20001

An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the logi

5.5
CVE-2025-21615

AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling.

5.5
CVE-2025-21592

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Junip

5.5
CVE-2018-9379

In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a c

5.5
CVE-2023-40108

In multiple locations, there is a possible way to access media content belonging to another user due to a missing permis

5.5
CVE-2024-49733

In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to

5.5
CVE-2025-22607

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

5.5
CVE-2024-54547

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Vent

5.5
CVE-2025-24109

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, ma

5.5
CVE-2025-24134

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3.

5.5
CVE-2025-24138

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started