cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory.
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Informati
An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a
An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to proper
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, ak
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo
In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching o
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka '
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locat
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle o
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
surf: cookie jar has read access from other local user
uzbl: Information disclosure via world-readable cookies storage file
libuser has information disclosure when moving user's home directory
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. Th
An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle o
An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle o
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomple
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world r
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date,
Adobe Connect versions 9.8.1 and earlier have a session token exposure vulnerability. Successful exploitation could lead
OX App Suite 7.8.4 and earlier allows Information Exposure.
ARM Trusted Firmware-A allows information disclosure.
Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANS
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started