Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiAnalyzer versions 7.2.0 th
A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >
In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, p
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to ac
Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environm
IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB cred
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local
IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the admi
Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allo
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could disclose sensitive information to an authenti
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive inform
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 o
A vulnerability was found in paxswill EVE Ship Replacement Program 0.12.11. It has been rated as problematic. This issue
Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template funct
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-l
Information disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialize
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in v
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to
Directus is a real-time API and App dashboard for managing SQL database content. In versions prior to 9.16.0 users with
A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. Th
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privilege
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 o
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain a
The course participation report required additional checks to prevent roles being displayed which the user did not have
Authenticated users were able to enumerate other users' names via the learning plans page.
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not
A vulnerability, which was classified as problematic, was found in Xunrui CMS 4.61. Affected is an unknown function of t
A vulnerability was found in Xunrui CMS 4.61 and classified as problematic. Affected by this issue is some unknown funct
A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown
A vulnerability, which was classified as problematic, was found in SourceCodester Grade Point Average GPA Calculator 1.0
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_delete
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The UserImpactHandler for Growt
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Task Allocation System 1.0. Aff
A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic.
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform.
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking
A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by
Minio Console is the UI for MinIO Object Storage. Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the orig
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are
A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Af
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
Microsoft SharePoint Server Security Feature Bypass Vulnerability
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite b
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insec
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosi
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 o
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started