An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to
In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become u
In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of pr
Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank
RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials.
In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an atta
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The action xmlexport accepts the paramet
The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale a
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on th
NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the serve
WALLIX Access Manager 3.x through 4.0.x allows a remote attacker to access sensitive information.
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8
This issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app m
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user w
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server u
XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fiel
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position i
An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive i
Miniflux is a feed reader. Prior to version 2.0.43, an unauthenticated user can retrieve Prometheus metrics from a publi
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.0
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. Pri
Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect confide
The MediaProvider module has a vulnerability in permission verification. Successful exploitation of this vulnerability m
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office docu
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmwa
Ghost is an app for new-media creators with tools to build a website, publish content, send newsletters, and offer paid
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a vi
Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agen
ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request.
OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated
Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`s
ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 202
Anonymous user may get the list of existing users managed by the application, that could ease further attacks (see CVE-2
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Se
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Se
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was f
The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerabi
Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation o
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confi
Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confi
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit thi
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started