The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions
The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that disc
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Inform
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial num
Shopware is an open source e-commerce software. Due to an incorrect configuration in the `.htaccess` file, the configura
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unaut
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially craf
The Royal Elementor Addons plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, a
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attack
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an ins
The Essential Addons For Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions
An information disclosure in the web interface of Brocade Fabric OS versions before Brocade Fabric OS v9.2.0 and v9.1.1c
Exposure of sensitive information to an unauthorized actor in BIOS firmware for some Intel(R) NUCs may allow a privilege
The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized ac
A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has t
IBM InfoSphere Information Systems 11.7 could expose information about the host system and environment configuration. I
An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed
IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused
The Leyka plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.30.7
An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge
In WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' d
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensiti
IBM Security Verify Access OIDC Provider could disclose directory information that could aid attackers in further attack
The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the pay
Discourse is an open source platform for community discussion. User summaries are accessible for anonymous users even wh
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could
The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9
The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnera
This issue was addressed by removing the vulnerable code. This issue is fixed in watchOS 10.1, iOS 16.7.2 and iPadOS 16.
Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requ
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote
The responses for web queries with certain parameters disclose internal path of resources. This information can be used
Poorly constructed webap requests and URI components with special characters trigger unhandled errors and exceptions, d
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enume
Prometheus metrics are available without authentication. These expose detailed and sensitive information about the Yugab
A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this
A vulnerability classified as problematic was found in Maiwei Safety Production Control Platform 4.1. This vulnerability
A vulnerability, which was classified as problematic, has been found in Maiwei Safety Production Control Platform 4.1. T
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via s
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of othe
Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker t
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Conte
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collect
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bowo Debug Log Manager.This issue affects De
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifie
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started