CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 th
Nebari through 2024.4.1 prints the temporary Keycloak root password.
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be retu
A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4
A security agent link following vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local atta
toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, t
IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants.
Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the Wi
Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing
Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API retur
Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external stora
GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and p
A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initial
Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary informa
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authentica
A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exyn
An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prio
Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may af
Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSoc
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to vers
A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is th
A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuClo
discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP
A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unkno
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown par
A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects un
A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vuln
A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is
TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being r
TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` U
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The support
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics
Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discuss
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch de
Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4
The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Ex
OroPlatform is a PHP Business Application Platform (BAP). A logged in user can access page state data of pinned pages o
OroPlatform is a PHP Business Application Platform (BAP). Navigation history, most viewed and favorite navigation items
The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added th
JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to sensitive information disclosure whereby a low-pr
Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site
A vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this
Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider co
A certain software build for the Sharp Rouvo V device (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:use
Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthent
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error mes
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started