Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the appl
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler. The information ex
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.This issue affects A
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership
Dell vApp Manager, versions prior to 9.2.4.x contain an information disclosure vulnerability. A remote attacker could p
An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certa
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitmen
Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri cal
Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.
Payload is a free and open source headless content management system. In versions prior to 1.7.0, if a user has access t
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K
Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other op
A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability
Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana c
Information disclosure in Kernel due to indirect branch misprediction.
Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to
Windows Error Reporting Service Elevation of Privilege Vulnerability
JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, pote
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability
Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the
Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Wi
IBM Cloud Pak for Security (CP4S) 1.9.0.0 through 1.9.2.0 could allow an attacker with a valid API key for one tenant to
AccessControl provides a general security framework for use in Zope. Python's "format" functionality allows someone cont
Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are no
Symantec Protection Engine, prior to 9.1.0, may be susceptible to a Hash Leak vulnerability.
This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1, wa
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all allows File Discovery. Th
Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenti
Mattermost Sever fails to redact the DB username and password before emitting an application log during server initializ
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the con
There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain an information
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information
Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified r
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and
The issue was addressed with improved UI handling. This issue is fixed in Safari 15.6, iOS 15.6 and iPadOS 15.6. Visitin
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect s
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Fil
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. I
libmemcached-awesome is an open source C/C++ client library and tools for the memcached server. `libmemcached` could ret
Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Man
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started