Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a use
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software has
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows us
Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who us
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a co
Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in
Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensit
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged application
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers t
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC i
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same devi
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may al
An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allo
Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information dis
Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects:
Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS))
Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 a
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version
A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed j
A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.1
An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.
IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has
In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about inst
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance informati
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts informat
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance informati
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in pla
Insecure configuration of default ObjectMapper in com.vaadin:flow-server versions 3.0.0 through 3.0.5 (Vaadin 15.0.0 thr
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELN
Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leak
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise
The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attac
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EX6100v2 before 1.0.1.106, EX6
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps director
It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on i
Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerab
Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device inform
An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST,
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an a
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started