IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log
An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to proper
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashin
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to th
This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Samsung Email
Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, A
In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, d
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec
Secure display content could be accessed by third party trusted application after creating a fault in other trusted appl
An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdro
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an informatio
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a
An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, ak
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Wi
In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtai
Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to pot
In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permis
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insuffic
In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c al
In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Te
In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointin
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat
An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's sy
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions with
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running
PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produ
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bi
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote atta
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data
A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleContr
Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.
view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke
Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started