Microsoft Exchange Server Information Disclosure Vulnerability
A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license serv
Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attac
The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec
The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenti
The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including
GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at Wo
Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit
Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or schedu
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous
Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosur
Discourse is a platform for community discussion. Under certain conditions, a user badge may have been awarded based on
IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 22
Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress.
This vulnerability discloses build and services versions in the server response header.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without t
A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affect
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem ac
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the config
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensit
The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When chan
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task duri
Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retriev
A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacke
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the
An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuratio
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13,
A high privileged user who has access to transaction SM59 can read connection details stored with the destination for ht
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessibl
Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a littl
Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System)
Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, conta
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the pa
Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, a
Windows Defender Credential Guard Information Disclosure Vulnerability
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process in
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStateme
In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notificat
Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive info
A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kerne
Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive informat
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started