Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 112/154
7.5
CVE-2017-16059

mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16060

babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16063

node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16064

node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished b

7.5
CVE-2017-16065

openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16066

opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by n

7.5
CVE-2017-16067

node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16068

ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

7.5
CVE-2017-16069

nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16070

nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by n

7.5
CVE-2017-16071

nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16072

nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16073

noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16074

crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16075

http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16076

proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16077

mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm

7.5
CVE-2017-16078

shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16079

smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

7.5
CVE-2017-16080

nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16081

cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished b

7.5
CVE-2017-16202

The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser

7.5
CVE-2017-16203

The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party se

7.5
CVE-2017-16204

The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server du

7.5
CVE-2017-16205

The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser

7.5
CVE-2017-16206

The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party se

7.5
CVE-2017-16225

aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled an

7.5
CVE-2018-4221

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The is

7.5
CVE-2018-12089

In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cl

7.5
CVE-2016-9904

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon

7.5
CVE-2017-5378

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address c

7.5
CVE-2017-5382

Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for th

7.5
CVE-2017-5385

Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy r

7.5
CVE-2017-5425

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matc

7.5
CVE-2017-5454

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files tha

7.5
CVE-2017-7759

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs,

7.5
CVE-2017-7787

Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes

7.5
CVE-2017-7843

When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprin

7.5
CVE-2018-5115

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed

7.5
CVE-2018-5134

WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache",

7.5
CVE-2018-5137

A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. Thi

7.5
CVE-2018-5157

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th

7.5
CVE-2018-5181

If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process

7.5
CVE-2018-5182

If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the a

7.5
CVE-2018-12592

Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when

7.5
CVE-2018-12594

Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct reques

7.5
CVE-2018-12735

SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inve

7.5
CVE-2018-0584

IIJ SmartKey App for Android version 2.1.0 and earlier allows remote attackers to bypass authentication [effect_of_bypas

7.5
CVE-2018-1000535

lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module tha

7.5
CVE-2018-10663

An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started