HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to a
Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine conf
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashi
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) befo
rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Ra
Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.
A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2
node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client err
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP
Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unp
An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write dat
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pur
The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read gl
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the l
Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally auth
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6400v2 before 1.0.4.84, R6700
A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authent
Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If
In onCreateOptionsMenu of WifiNetworkDetailsFragment.java, there is a possible way for guest users to view and modify Wi
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 2.8.0, when the ajax endpoint
Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosu
Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, R
When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed,
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to informati
In Directus 8.x through 8.8.1, an attacker can see all users in the CMS using the API /users/{id}. For each call, they g
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0
An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the
When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send
The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than
In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible
The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that
Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files ins
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to al
A flaw was found in ImageMagick in versions before 7.0.11. A potential cipher leak when the calculate signatures in Tran
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, a
Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly disco
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trig
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed ema
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because th
Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive i
A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this c
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud
Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 all
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attack
Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks
An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03.
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response whe
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started