Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BogdanFix WP SendFox wp-sendfox allows Retri
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi
A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allow
A vulnerability, which was classified as problematic, was found in ZZCMS 2023. This affects an unknown part of the file
The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenti
The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure
A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 202410
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon
The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, re
The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This i
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
The Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure
The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable t
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versio
An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affe
The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u
The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information
An AirVantage online Warranty Checker tool vulnerability could allow an attacker to perform bulk enumeration of IMEI an
A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and clas
A vulnerability classified as problematic has been found in Amcrest IP2M-841B, IP2M-841W, IPC-IP2M-841B, IPC-IP3M-943B,
Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin).
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7
Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through
Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information
TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLO
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or
CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the pat
Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any coll
The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the v
vaeThink 1.0.2 is vulnerable to Information Disclosure via the system backend,access management administrator function.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions start
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a pri
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a Wor
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started