Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service
Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive informa
The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the
Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensiti
Hardcoded TLS private key and certificate in firmware in Kiloview N30 2.02.246 allows malicious adversary to do a Mann-i
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Central
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Transla
In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-value
In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Ad
The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing
A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability a
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, whe
A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Applicati
Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_
The web interface of the Silicon Labs Simplicity Device Manager is exposed publicly and can be used to extract the NTLMv
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized
Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through
Exposure of password hashes through an unauthenticated API response in TP-Link Tapo app on iOS and Android for Tapo came
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsContr
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the data
Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerabi
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted m
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated R
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowled
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that o
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of cr
The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions
Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicCon
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex
Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the
Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service a
DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by an
rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Auror
An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstnam
An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in
By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read a
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's
Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to a
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unautho
In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.Password
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue af
For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to
The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missin
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started