Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/Err
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information fr
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecur
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call th
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack
The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover
The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow an attacker to sniff private informa
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a dire
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vuln
The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authoriz
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that should
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The informatio
All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use MAC addresses
IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information
On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLease
CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 1
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive ph
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file passwo
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that co
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive info
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address.
An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to ope
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /da
Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information relat
Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to ret
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final fil
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2.
IBM QRadar Advisor with Watson 1.14.0 discloses sensitive information to unauthorized users. The information can be used
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users. Th
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 discloses sensitive information to
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster respon
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.p
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/che
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive inf
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside o
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges
Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupporte
In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive informat
IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IB
cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidd
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden N
The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signa
A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /regi
IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the us
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started