In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MD
On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to b
The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edit
The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition b
An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies p
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, when writi
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, there coul
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small C
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and S
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and S
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400,
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9650, SD 210/SD 212/SD 205
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD
In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdrag
In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdrag
Pivotal Gemfire for PCF, versions 1.6.x prior to 1.6.5.0 and 1.7.x prior to 1.7.1.0, contain an information disclosure v
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP chann
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes
Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploit
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b
A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a
`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished
`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished b
`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished
`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished b
`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by
Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a cra
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started