Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1,
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python
A vulnerability was found in Evolution Events Artaxerxes. It has been declared as problematic. This vulnerability affect
Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.be
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/user
A vulnerability has been found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this
Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later t
Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such
A vulnerability was found in yhz66 Sandbox 6.1.0. It has been rated as problematic. Affected by this issue is some unkno
A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknow
A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected by this issue is some un
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to version 1.13.4, when
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments
A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing
Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or P
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps,
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Camel.This
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0,
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other gr
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Teli
Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may
IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modi
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by
discourse-yearly-review is a discourse plugin which publishes an automated Year in Review topic. In affected versions a
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized att
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. Thi
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the Leas
A vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown co
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection
Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for ot
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API en
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API e
A vulnerability has been found in what3words Autosuggest Plugin up to 4.0.0 on WordPress and classified as problematic.
Wagtail is an open source content management system built on Django. A user with a limited-permission editor account for
IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a privileged user to obtain sensitive information due to mi
A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknow
Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physica
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggl
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Teli
A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local accou
Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated use
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application err
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered i
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting wit
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started