Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposu
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PH
The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7
The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ
codeshare v1.0.0 was discovered to contain an information leakage vulnerability.
The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endp
Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below,
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive I
The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure i
The Comment Edit Core – Simple Comment Editing plugin for WordPress is vulnerable to Sensitive Information Exposure in a
The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote at
The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu
The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all vers
The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versi
The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'locker
The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc
The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.
Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the ex
The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio
The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and
The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in a
The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of
A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientr
A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit
A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of th
The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i
To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post o
The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local inform
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation
Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd A
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com
An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a C
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started