Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerabi
Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, s
SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u
angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker contain
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively us
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulne
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - version
Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password h
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vu
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorize
Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, whi
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ON
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration fil
The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability ma
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administra
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability an
A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled
Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, an
Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows
Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apa
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tina
Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability
Strapi is an open-source headless content management system. Prior to version 4.10.8, it is possible to leak private fie
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensi
JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of u
Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in
IBM QRadar SIEM 7.4 and 7.5copies certificate key files used for SSL/TLS in the QRadar web user interface to managed ho
Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerabil
Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical info
Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to ret
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token an
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send cra
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token
Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated
Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phra
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permiss
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privi
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desk
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in version
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of cala
Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability
The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.
A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as
Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts Git
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started