Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safet
The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitiv
An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 1
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment
An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications u
Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapd
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful expl
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful expl
An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenti
In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fa
Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope.
Scrapy-splash is a library which provides Scrapy and JavaScript integration. In affected versions users who use [`HttpAu
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK50 before 2.7.3.22, RBR50 b
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exist in AccuSine PCS+ / PFV+ (Versi
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) a
wire-webapp is an open-source front end for Wire, a secure collaboration platform. In wire-webapp before version 2021-03
An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticated attacker to elevat
Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1
MuWire is a file publishing and networking tool that protects the identity of its users by using I2P technology. Users o
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directori
Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows
wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attach
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes passwo
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause in
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials thro
Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for
Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lo
Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utiliz
Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in T
An Exposure of System Data vulnerability in Juniper Networks Junos OS and Junos OS Evolved, where a sensitive system-lev
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.
A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensiti
A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remot
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.
The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (
The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number i
Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199
Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated datab
A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an aut
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could dow
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling.
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started