A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104/4.2.0.101. It has been
A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of th
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 fo
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics whi
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfi
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 1
Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2
Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentic
A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component U
A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attac
Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Micr
A weakness has been identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is some unknown functionality
A security flaw has been discovered in FNKvision Y215 CCTV Camera 10.194.120.40. This affects an unknown part of the fil
@codidact/qpixel is a Q&A-based community knowledge-sharing software. In affected versions when a category is set to pri
A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifyi
kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vec
PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing key
GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the
Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker
Shescape is a simple shell escape library for JavaScript. Versions 1.7.2 through 2.1.1 are vulnerable to potential envir
MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that impl
Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulne
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Mobile
KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join yo
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Crestron Automate VX allows Functionality Mi
conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web inter
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the
An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/conf
A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket
A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat
A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.
An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause pa
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An un
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This to
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized a
claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due t
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started