php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or o
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for ma
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access
Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative executi
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the devi
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC
On EX4300 Series switches with TCAM optimization enabled, incoming multicast traffic matches an implicit loopback filter
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows loc
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execu
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution m
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfull
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.1
Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM965
Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206,
Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206
Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM
An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android m
Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to o
In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed wi
Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile a
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no
Usage of non-time-constant comparison functions can lead to information leakage through side channel analysis in Snapdra
An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version
An information disclosure issue was addressed by removing the vulnerable code. This issue affected versions prior to mac
A configuration issue was addressed with additional restrictions. This issue affected versions prior to iOS 12, macOS Mo
A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting opt
A lock screen issue allowed access to photos and contacts on a locked device. This issue was addressed by restricting op
This issue was addressed by removing additional entitlements. This issue affected versions prior to macOS Mojave 10.14.1
A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.
Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asse
The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain s
NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may acces
The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obta
The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users
Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component
ECDSA signature code leaks private keys from secure world to non-secure world in Snapdragon Auto, Snapdragon Compute, Sn
Secure keypad is unlocked with secure display still intact in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer E
Possible memory overread may be lead to access of sensitive data in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons
Failure to initialize the reserved memory which is sent to the firmware might lead to exposure of 1 byte of uninitialize
Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory, aka 'Micros
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started