Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the ch
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious auth
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipi
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote at
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up
The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosu
The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk
The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi
The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Inf
OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that ca
A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been clas
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, i
Navidrome is an open source web-based music collection server and streamer. In affected versions of Navidrome are subjec
Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept t
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 pr
Element Android is an Android Matrix Client. A third-party malicious application installed on the same phone can force E
Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vul
Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability ma
Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-or
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker w
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is a
A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Com
IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709
Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to
A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 2024040
A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown fu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Function
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Webcraftic Hide login page allows Accessing
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hid
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Acc
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in All In One WP Security & Firewall Team All I
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administr
A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue i
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including
A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvert
HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the u
MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions ca
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in
HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server err
This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability i
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started