semantic-release is an open source npm package for automated version management and package publishing. In affected vers
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the
IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IB
Discourse is an open source platform for community discussion. In affected versions when composing a message from topic
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8
Discourse is an open source discussion platform. Discourse groups can be configured with varying visibility levels for t
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and
Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, w
Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the For
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remot
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server inform
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allo
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users A
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with
Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###Acc
An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or
Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should b
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authe
A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat fro
Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to ve
Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own s
When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response,
A flaw was found in moodle where global search results could include author information on some activities where a user
A vulnerability has been found in Klapp App and classified as problematic. This vulnerability affects unknown code of th
A vulnerability classified as problematic was found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this vulnerabilit
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29,
discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of se
A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an un
A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior
Address information disclosure vulnerability in Cybozu Garoon 4.2.0 to 5.5.1 allows a remote authenticated attacker to o
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allo
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the PFE of Juniper Networks Junos OS on P
A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerab
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo
A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enoug
An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw
Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an at
An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to the actionLinkHandler meth
An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets
An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 since the getReadReceipts Meteor
A information disclosure vulnerability exists in Rockert.Chat <v5 due to /api/v1/chat.getThreadsList lack of sanitizatio
A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in t
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started