The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 d
The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t
An issue in AnkiDroid Android Application v2.17.6 allows attackers to retrieve internal files from the /data/data/com.ic
A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic.
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Info
The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin
Mastodon is a self-hosted, federated microblogging platform. In versions prior to 4.1.23, 4.2.16, and 4.3.4, when the vi
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in
A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security
The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin
An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Info
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Sensitive Information Exposu
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15,
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensit
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and p
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosu
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS versi
SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials t
The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring un
Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*.
Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entit
Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25
Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By
The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between
The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in
A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users
The Cart66 Cloud plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
The Developer Toolbar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that
The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and
The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure
A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affec
The Yame | Link In Bio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown f
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerabi
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote
A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Mana
A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classifie
A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). This issu
A vulnerability, which was classified as problematic, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected is an
A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this
A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this issue
A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started