Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost
The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insuf
In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes
front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive informati
The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allow
gpt_academic provides a graphical interface for ChatGPT/GLM. A vulnerability was found in gpt_academic 3.37 and prior. T
The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2
Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a sp
In Apache Airflow, some potentially sensitive values were being shown to the user in certain situations. This vulnerabi
IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific doma
Microsoft Teams Information Disclosure Vulnerability
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access t
Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authentic
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.
KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 lea
Microsoft SharePoint Server Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. O
yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file incl
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automati
Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated users who have access to
An information leak in kokoroe_members card Line 13.6.1 allows attackers to obtain the channel access token and send cra
An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted m
An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFil
Apache Airflow, versions before 2.7.2, has a vulnerability that allows an authorized user who has access to read specifi
Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposu
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL
IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain
A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possib
Apache Airflow, versions before 2.7.3, has a vulnerability that allows an authorized user who has access to read specifi
Open Management Infrastructure Information Disclosure Vulnerability
The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versio
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce plugin
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce.This is
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affe
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Leap13 Premium Addons PRO.This issue affects
Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint
Microsoft Outlook Information Disclosure Vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Media File Renamer: Rename Files
Sensitive data was added to our public-facing knowledgebase that, if exploited, could be used to access components of Ac
Dell Hybrid Client version 2.0 contains a Sensitive Data Exposure vulnerability. An unauthenticated malicious user on t
Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As i
SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensi
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive informa
Information Disclosure in Graphics during GPU context switch.
A vulnerability has been identified in SIMATIC IPC1047 (All versions), SIMATIC IPC1047E (All versions with maxView Stora
Information disclosure in DSP Services while loading dynamic module.
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started