A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unkn
A vulnerability was found in PlayTube 3.0.1 and classified as problematic. This issue affects some unknown processing of
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 t
A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows at
The Easy Registration Forms for WordPress is vulnerable to Information Disclosure via the 'erforms_user_meta' shortcode
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a me
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2,
Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve s
MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user c
A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPr
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a speciall
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `clien
The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in v
The Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessa
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Air
capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used
An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may
Zulip is an open-source team collaboration tool. It was discovered by the Zulip development team that active users who h
An issue was discovered on Bell HomeHub 3000 SG48222070 devices. Remote authenticated users can retrieve the serial numb
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0co
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16
Mattermost fails to check whether the “Allow users to view archived channels” setting is enabled during permalink prev
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a me
An authenticated user with read permissions on database connections metadata could potentially access sensitive informat
IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote authenticated user
Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active
ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Pro
Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configu
urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to acce
Apereo CAS is an open source multilingual single sign-on solution for the web. Apereo CAS can be configured to use authe
In some configuration scenarios, the Domino server host name can be exposed. This information could be used to target fu
IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclo
IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitiv
Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated
Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability whic
Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authoriza
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos t
Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Ex
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously u
UmbracoIdentityExtensions is an Umbraco add-on package that enables easy extensibility points for ASP.Net Identity integ
TYPO3 is an open source PHP based web content management system. Starting in version 9.4.0 and prior to versions 9.5.42
IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts,
vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the linked resources
Discourse is an open source platform for community discussion. Attackers with details specific to a poll in a topic can
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the log
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started