IBM WebSphere eXtreme Scale 8.6.1 stores sensitive information in URL parameters. This may lead to information disclosur
IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote user to obtain sensitive information from HTTP response h
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local
Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (bas
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem arti
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients
It was possible for some users without permission to view other users' full names to do so via the online users block in
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or n
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Acto
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked t
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s
Microsoft SharePoint Server Information Disclosure Vulnerability
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumera
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch sugges
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Sec
IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in furth
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doub
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RT
Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Man
Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in
Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, par
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and in
Observable behavioral discrepancy vulnerability in QSAN Storage Manager allows remote attackers to obtain the system inf
Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticate
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further atta
A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.
Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe componen
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used
NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions availabl
Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limit
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database
IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information discl
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemet
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosur
Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application pu
InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerabi
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affec
An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the
Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discov
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remo
Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitiv
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented b
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started