Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 49/154
6.5
CVE-2024-2093

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up

6.5
CVE-2024-29987

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

6.5
CVE-2024-32051

Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is

6.5
CVE-2024-1102

A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as

6.5
CVE-2023-35750

D-Link DAP-2622 DDP Get SSID List WPA PSK Information Disclosure Vulnerability. This vulnerability allows network-adjace

6.5
CVE-2024-3182

Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versi

6.5
CVE-2024-35189

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `Conne

6.5
CVE-2021-44534

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive

6.5
CVE-2024-34002

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with

6.5
CVE-2024-34004

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with

6.5
CVE-2024-34005

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with

6.5
CVE-2024-35691

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extende

6.5
CVE-2020-11843

This allows the information exposure to unauthorized users. This issue affects NetIQ Access Manager using version 4.5 or

6.5
CVE-2024-0093

NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not

6.5
CVE-2024-21685

This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Cor

6.5
CVE-2024-39313

toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, a

6.5
CVE-2024-38020

Microsoft Outlook Spoofing Vulnerability

6.5
CVE-2024-38030

Windows Themes Spoofing Vulnerability

6.5
CVE-2022-45449

Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affec

6.5
CVE-2024-39817

Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user

6.5
CVE-2024-34788

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to ac

6.5
CVE-2024-38200

Microsoft Office Spoofing Vulnerability

6.5
CVE-2024-39822

Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an auth

6.5
CVE-2024-43251

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit

6.5
CVE-2024-43257

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.

6.5
CVE-2024-8106

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in

6.5
CVE-2024-39925

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who l

6.5
CVE-2024-8780

OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote

6.5
CVE-2024-8969

OMFLOW from The SYSCOM Group has a vulnerability involving the exposure of sensitive data. This allows remote attackers

6.5
CVE-2024-42351

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools,

6.5
CVE-2024-45792

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered

6.5
CVE-2024-47532

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote

6.5
CVE-2024-43609

Microsoft Office Spoofing Vulnerability

6.5
CVE-2024-21205

Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The s

6.5
CVE-2024-22032

A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption confi

6.5
CVE-2024-20457

A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM I

6.5
CVE-2024-52506

Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and sched

6.5
CVE-2024-53858

The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that c

6.5
CVE-2024-53859

go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerab

6.5
CVE-2024-10548

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i

6.4
CVE-2024-21902

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operatin

6.3
CVE-2024-36986

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9

6.3
CVE-2020-25836

Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Admin

6.3
CVE-2024-41109

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` wi

6.3
CVE-2021-22529

A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects N

6.3
CVE-2024-46548

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eave

6.3
CVE-2024-20490

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orches

6.3
CVE-2024-20491

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech su

6.3
CVE-2024-8553

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authent

6.3
CVE-2024-46894

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started