node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and n
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attac
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the co
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-s
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentic
IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to obtain sensitive information, caused by the fai
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of informat
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could
git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a serie
IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorr
Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vuln
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server han
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Ap
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information,
An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Appli
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider c
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C56
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 al
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an atta
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitr
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentia
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure
The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant befor
The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/sim
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows i
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server 2008 R2, and Window
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows i
A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 thro
A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 befor
Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions befor
Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C57
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started