A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects so
A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function
In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which
In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Sec
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server info
The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization
Windows BitLocker Information Disclosure Vulnerability
The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.8.9, in CI
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18
Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthoriz
Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect
Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may af
Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect ser
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive in
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function send
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The ma
A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/passwor
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.
A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onp
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlock
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Discourse Policy plugin gives the ability to confirm users have seen or done something. Prior to version 0.1.1, if there
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive inf
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthor
There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control me
A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality
LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to d
In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.11
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, throu
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the func
GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3,
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompressio
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon
A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the f
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in iOS 26.1 and iPadOS
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS
EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by thei
Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can b
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1
A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes ce
A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component G
A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator o
Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affe
The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started