Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 105/154
4.7
CVE-2019-1009

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1010

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1011

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1012

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1013

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1015

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1016

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1046

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1047

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1048

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1049

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-1050

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

4.7
CVE-2019-18660

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place

4.6
CVE-2018-1874

IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access t

4.6
CVE-2018-4388

A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting opt

4.6
CVE-2019-1589

A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switch

4.6
CVE-2018-18056

An issue was discovered in the Texas Instruments (TI) TM4C, MSP432E and MSP432P microcontroller series. The eXecute-Only

4.6
CVE-2019-16285

If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extra

4.6
CVE-2019-10224

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and ds

4.5
CVE-2019-3803

Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote atta

4.4
CVE-2018-5497

Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability which discloses sensi

4.4
CVE-2019-1762

A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attac

4.4
CVE-2019-1731

A vulnerability in the SSH CLI key management functionality of Cisco NX-OS Software could allow an authenticated, local

4.4
CVE-2018-20889

cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).

4.4
CVE-2019-1202

An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated

4.4
CVE-2019-9444

In the Android kernel in sync debug fs driver there is a kernel pointer leak due to the usage of printf with %p. This co

4.3
CVE-2018-15456

A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke

4.3
CVE-2018-2026

IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory lis

4.3
CVE-2019-1645

A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attack

4.3
CVE-2019-1657

A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information.

4.3
CVE-2019-1003018

An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in Gi

4.3
CVE-2019-1003021

An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlie

4.3
CVE-2018-1949

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information

4.3
CVE-2018-1950

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that

4.3
CVE-2018-1929

IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view

4.3
CVE-2018-13290

Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote a

4.3
CVE-2018-13291

Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824

4.3
CVE-2018-13292

Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allo

4.3
CVE-2018-13294

Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows rem

4.3
CVE-2018-13295

Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 a

4.3
CVE-2018-1625

IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive info

4.3
CVE-2018-4445

"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This is

4.3
CVE-2018-1999

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could reveal sensitive version information about the s

4.3
CVE-2018-18511

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImage

4.3
CVE-2018-2008

IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that coul

4.3
CVE-2017-1107

IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by a

4.3
CVE-2018-1734

IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 discloses sensitive information in error messages th

4.3
CVE-2018-6177

Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin d

4.3
CVE-2019-11268

Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious

4.3
CVE-2019-8286

Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 201

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started