LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp
LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass a
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Scribit GDPR Compliance.This issue affects G
An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api
In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only chang
Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET r
The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that
Import functionality is vulnerable to DNS rebinding attacks between verification and processing of the URL. Project adm
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthen
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API
In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credi
In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specia
Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted que
Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page par
An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root u
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information fo
Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combin
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affect
An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pin
DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading
Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthoriz
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improp
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issu
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) to
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Paym
A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerabilit
An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v
Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affect
Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/ap
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prio
D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration
Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.
Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0
OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read ar
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in M
The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and conten
Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affe
An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update
An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive in
An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive inform
An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started