A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail v
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive version information in HTTP response headers
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supp
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (dire
BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new u
A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affec
Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "p
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in po
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status
Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing conf
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid request
SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.1
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplie
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made
A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability
Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote att
Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior
HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability du
Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visito
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows a
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page sour
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capa
IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to in
On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: So
Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers.
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that coul
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co
A vulnerability, which was classified as problematic, has been found in Axios Italia Axios RE 1.7.0/7.0.0. This issue af
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause th
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based
The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted reque
Discourse is an open-source discussion platform. Prior to version 2.8.4 in the `stable` branch and version `2.9.0.beta5`
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an
The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20
Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1
mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, eve
DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started