All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the c
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 thr
The IBM Storwize V7000 Unified management Web interface 1.6 exposes internal cluster details to unauthenticated users. I
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows S
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter valu
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a u
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsist
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they h
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monit
IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive inform
The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is kno
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-o
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that other
A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible throug
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta
The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin cont
Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise p
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv
Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN param
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account i
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass
Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' page
IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information
phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is i
The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches runn
IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a remote attacker to download certain files that could contain
IBM Sterling B2B Integrator Standard Edition 5.2 through 5.2.6 could allow an unauthenticated user to obtain sensitive i
In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERA
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 discloses sensitive information to unauthorized u
HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier tha
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerab
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an ex
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from v
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictab
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started