Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would othe
FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sens
It was observed that while login into Business-central console, HTTP request discloses sensitive information like userna
The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's bookin
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications
Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default,
An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated att
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and
In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address tha
TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib conf
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of t
A vulnerability has been found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as problematic. This vulnerability a
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive informatio
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive informa
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a worksp
Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.191012 allows attackers to obtain sensitive rout
A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive ro
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.
IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to
Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's addr
An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS
An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be
There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was ca
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src
A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled b
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 1
smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, wh
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web ap
ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and
A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for task
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to vers
An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers t
AMI MegaRAC User Enumeration Vulnerability
A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versi
The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may a
Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows at
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.
The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions p
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started