A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business
The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Dire
A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the
A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerabi
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leak
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMin
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoi
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified
An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attack
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unk
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/u
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query f
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in vers
The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.
A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the f
A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of
A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/
A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patien
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ b
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri
Missing authorization checks in the CSV download feature of TYPO3 CMS versions 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and metho
A security flaw has been discovered in kaifangqian kaifangqian-base up to 7b3faecda13848b3ced6c17c7423b76c5b47b8ab. This
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open
The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versi
Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server).
Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden g
An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return s
A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is som
A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.
On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user
The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,
The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9.
A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sen
Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve
An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all
Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes no
In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitm
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment r
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started