In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any un
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and be
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=r
NETGEAR R7000 devices before 1.0.11.116 are affected by disclosure of sensitive information.
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O
Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker ab
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6
In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed,
A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specif
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows re
The management system of ZXCDN is impacted by the information leak vulnerability. Attackers can make further analysis ac
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Servic
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virt
SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information i
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to version
Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an erro
Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Andr
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Forc
Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub a
Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidd
The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadat
Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-
IBM Cloud Pak for Security (CP4S) 1.3.0.1 could disclose sensitive information through HTTP headers which could be used
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Di
When dynamic templates are used (OTRSTicketForms), admin can use OTRS tags which are not masked properly and can reveal
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all ve
IBM Planning Analytics 2.0 could allow a remote authenticated attacker to obtain information about an organization's int
Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME
Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authentic
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Leve
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilato
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the par
Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccess
An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller serve
In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to tri
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can l
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. Its AbuseFilterCheckMatch API reveals
An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The Special:AbuseFilter/examine form
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to informati
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentia
A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote
Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by defa
A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspa
An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially craft
Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started