An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memo
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online ser
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock op
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.
An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'.
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to
Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memo
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allo
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allo
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allo
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitiv
D-Link DIR-865L has Information Disclosure.
An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within over
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added
A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to do
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBo
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature.
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before
Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obta
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cros
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or lat
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking mer
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when th
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October
mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started