A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact coul
Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnera
Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability m
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFL
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive infor
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the a
Cloud Explorer Lite is an open source cloud management platform. Prior to version 1.4.0, there is a risk of sensitive in
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an un
Sensitive information disclosure due to excessive collection of system information. The following products are affected:
An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitiv
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.
Microsoft Outlook Information Disclosure Vulnerability
An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via g
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInf
Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect
In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause se
A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an inse
Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability
Vulnerability of package names' public keys not being verified in the security module.Successful exploitation of this vu
Vulnerability of the permission to access device SNs being improperly managed.Successful exploitation of this vulnerabil
Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticate
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apa
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported v
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieva
The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-
EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via craf
An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET reque
An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
An information disclosure vulnerability in the component users-grid-data.php of Ocomon before v4.0.1 allows attackers to
An information leak in Gyouza-newhushimi v13.6.1 allows attackers to obtain the channel access token and send crafted me
An information leak in shouzu sweets oz v13.6.1 allows attackers to obtain the channel access token and send crafted mes
An information leak in Tokudaya.honten v13.6.1 allows attackers to obtain the channel access token and send crafted mess
An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted
An information leak in VISION MEAT WORKS Track Diner 10/10mbl v13.6.1 allows attackers to obtain the channel access toke
An information leak in Hattoriya v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
An information leak in Tokudaya.ekimae_mc v13.6.1 allows attackers to obtain the channel access token and send crafted m
An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-g
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transac
Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerabilit
Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may aff
The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started