Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 102/154
5.5
CVE-2018-20902

cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).

5.5
CVE-2017-18396

cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).

5.5
CVE-2019-1078

An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory.

5.5
CVE-2019-1143

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

5.5
CVE-2019-1154

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

5.5
CVE-2019-1158

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

5.5
CVE-2019-1227

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker

5.5
CVE-2019-1228

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker

5.5
CVE-2017-18549

An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure

5.5
CVE-2017-18550

An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure

5.5
CVE-2019-2103

In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot

5.5
CVE-2019-1216

An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Informati

5.5
CVE-2019-1219

An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory

5.5
CVE-2019-1251

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di

5.5
CVE-2019-1263

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka

5.5
CVE-2019-1283

An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a

5.5
CVE-2019-1293

An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to proper

5.5
CVE-2019-1334

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window

5.5
CVE-2019-1337

An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, ak

5.5
CVE-2019-1363

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec

5.5
CVE-2019-1369

An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo

5.5
CVE-2019-2183

In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching o

5.5
CVE-2013-4518

RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates

5.5
CVE-2019-1734

A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could

5.5
CVE-2019-1370

An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo

5.5
CVE-2019-1374

An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka '

5.5
CVE-2019-1381

An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locat

5.5
CVE-2019-1402

An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle o

5.5
CVE-2019-1436

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi

5.5
CVE-2019-1440

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi

5.5
CVE-2019-1446

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka

5.5
CVE-2012-0842

surf: cookie jar has read access from other local user

5.5
CVE-2012-0843

uzbl: Information disclosure via world-readable cookies storage file

5.5
CVE-2012-5644

libuser has information disclosure when moving user's home directory

5.5
CVE-2012-1105

An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. Th

5.5
CVE-2019-1400

An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle o

5.5
CVE-2019-1463

An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle o

5.5
CVE-2019-1464

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka

5.5
CVE-2019-1469

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi

5.5
CVE-2019-1472

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window

5.5
CVE-2019-1474

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window

5.5
CVE-2019-4444

IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomple

5.5
CVE-2012-5476

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world r

5.4
CVE-2019-10156

A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing

5.3
CVE-2018-16876

ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on

5.3
CVE-2018-5738

Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date,

5.3
CVE-2018-19718

Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead

5.3
CVE-2018-12610

OX App Suite 7.8.4 and earlier allows Information Exposure.

5.3
CVE-2018-19440

ARM Trusted Firmware-A allows information disclosure.

5.3
CVE-2019-7312

Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANS

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started