The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1
CNCF Harbor 2.13.x before 2.13.1 and 2.12.x before 2.12.4 allows information disclosure by administrators who can exploi
A vulnerability in the debug logging function of Cisco Duo Authentication Proxy could allow an authenticated, high-privi
An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.p
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Appli
Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows sy
Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma
App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerabi
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits incons
Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, du
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge
In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or
A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an ex
Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync a
BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious f
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious form
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visio
An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with phys
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary com
In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local in
A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticat
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose in
Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may
A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examinati
A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2
A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.2108
The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all
The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to
The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure
CloudStack users can add and read comments (annotations) on resources they are authorised to access. Due to an access
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sili
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not
A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secur
Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) dem
A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerab
The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all
A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an un
This issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, ma
A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user d
A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance mana
A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student
A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unkn
A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unkn
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started