Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.
Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affec
Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section
Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other s
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length
In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to hap
Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad
Windows Kerberos Information Disclosure Vulnerability
The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive In
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure
Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the
The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by
Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enab
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Mult
The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data e
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu
Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows
The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all
GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anony
A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fd
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclos
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6
APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com
There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface
There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interfa
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the logi
AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling.
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Junip
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a c
In multiple locations, there is a possible way to access media content belonging to another user due to a missing permis
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Vent
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, ma
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3.
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started