A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for furthe
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated atta
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data t
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public cl
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder AP
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS
A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communica
ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password t
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Re
Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headles
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected vers
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access r
@replit/crosis is a JavaScript client that speaks Replit's container protocol. A vulnerability that involves exposure of
Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server witho
mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker
Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middlewar
An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with oth
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linu
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroa
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated
An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that cou
Dell GeoDrive, versions 2.1 - 2.2, contains an information disclosure vulnerability in GUI. An authenticated non-admin u
A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Managemen
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versio
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In af
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, c
Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can g
Under certain conditions an authenticated attacker can get access to OS credentials. Getting access to OS credentials en
Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation o
MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of t
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_
Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID:
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authori
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to ve
A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started