An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via th
An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attack
OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthentica
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all
Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, whic
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is ena
VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an unaut
A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker
An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerabi
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When us
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to
Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, e
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A co
Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access
Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker
FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/b
Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious acto
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) func
In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix module reference leak A refere
Windows NTLM Spoofing Vulnerability
SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definitio
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive inform
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9
VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access
Windows Themes Spoofing Vulnerability
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Co
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPad
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue af
Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purc
As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of th
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets w
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-ch
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to creat
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Elementor Pro.This issue affects Elementor P
Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all mes
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects
Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This is
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Elite for WooCommerce.This i
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started