The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as
D-Link DAP-2622 DDP Get SSID List WPA PSK Information Disclosure Vulnerability. This vulnerability allows network-adjace
Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versi
Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `Conne
Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extende
This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or
NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not
This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Cor
toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, a
Microsoft Outlook Spoofing Vulnerability
Windows Themes Spoofing Vulnerability
Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affec
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to ac
Microsoft Office Spoofing Vulnerability
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an auth
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in
An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who l
OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote
OMFLOW from The SYSCOM Group has a vulnerability involving the exposure of sensitive data. This allows remote attackers
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools,
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote
Microsoft Office Spoofing Vulnerability
Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The s
A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption confi
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM I
Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and sched
The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that c
go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerab
The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i
An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operatin
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9
Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Admin
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` wi
A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects N
TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eave
A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orches
A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech su
A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authent
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started