cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memo
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login
Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to us
An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Informat
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch nam
An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, c
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information wh
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
Moodle before 2.2.2: Overview report allows users to see hidden courses
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a
lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project mi
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, i
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x befo
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allo
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.
The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contac
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read
SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for bro
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x befo
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclos
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the
An issue was discovered in Open Ticket Request System (OTRS) 7.x before 7.0.5. An attacker who is logged into OTRS as an
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon '
Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059),
A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of
IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archi
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A m
In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.S
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'W
The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup.
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs wit
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to spoof connection information wh
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started