mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished b
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by n
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by np
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished b
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party se
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server du
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser
The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party se
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled an
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The is
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cl
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zon
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address c
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for th
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy r
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matc
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files tha
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs,
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprin
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed
WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache",
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. Thi
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th
If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the a
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when
Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct reques
SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inve
IIJ SmartKey App for Android version 2.1.0 and earlier allows remote attackers to bypass authentication [effect_of_bypas
lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module tha
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started