Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 122/154
5.3
CVE-2018-10729

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the c

5.3
CVE-2018-1465

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,

5.3
CVE-2013-3018

The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 thr

5.3
CVE-2018-1467

The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. I

5.3
CVE-2017-14185

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows S

5.3
CVE-2018-11517

mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter valu

5.3
CVE-2018-10732

The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a u

5.3
CVE-2018-11565

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames

5.3
CVE-2015-9236

Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsist

5.3
CVE-2018-11645

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow

5.3
CVE-2018-3809

Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they h

5.3
CVE-2018-10599

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monit

5.3
CVE-2017-1474

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive inform

5.3
CVE-2017-16126

The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is kno

5.3
CVE-2018-11409

Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json

5.3
CVE-2017-5408

Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o

5.3
CVE-2017-7808

A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against

5.3
CVE-2017-7812

If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that other

5.3
CVE-2017-7831

A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose

5.3
CVE-2017-7842

If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e

5.3
CVE-2018-5106

Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a

5.3
CVE-2018-5114

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible throug

5.3
CVE-2018-5118

The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta

5.3
CVE-2018-5119

The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin cont

5.3
CVE-2018-5140

Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p

5.3
CVE-2018-12227

An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert

5.3
CVE-2018-12522

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro

5.3
CVE-2018-12523

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi

5.3
CVE-2018-12524

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi

5.3
CVE-2018-12525

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr

5.3
CVE-2018-1073

The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv

5.3
CVE-2018-12632

Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN param

5.3
CVE-2017-7568

NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account i

5.3
CVE-2018-0575

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass

5.3
CVE-2018-1000549

Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' page

5.3
CVE-2018-1553

IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information

5.3
CVE-2018-12990

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

5.3
CVE-2016-9499

Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is i

5.3
CVE-2013-0570

The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches runn

5.3
CVE-2018-1398

IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain

5.3
CVE-2018-1679

IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive i

5.3
CVE-2018-14432

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERA

5.3
CVE-2017-1409

IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized u

5.3
CVE-2018-7070

HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier tha

5.3
CVE-2018-15599

The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerab

5.3
CVE-2018-15668

An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an ex

5.3
CVE-2018-15919

Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc

5.3
CVE-2018-13391

The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from v

5.3
CVE-2014-6048

phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.

5.3
CVE-2018-15684

An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictab

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started