A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in th
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to
Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar
OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a loc
Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress.
Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unautho
Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored cr
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially be
Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access int
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an u
Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an
Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.
Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connecte
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Port
Exposure of sensitive information in AT_Distributor prior to SMR Oct-2022 Release 1 allows local attacker to access Seri
Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers t
Implicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive
IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID:
IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS i
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to And
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot
Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server ex
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single characte
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0,
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
Wagtail is a Django based content management system focused on flexibility and user experience. When notifications for n
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of t
When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received
A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket custome
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the
Article template contents with sensitive data could be accessed from agents without permissions.
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr
Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulne
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently laun
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local a
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local atta
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to acce
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to acces
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers t
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started