Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-200

MITRE ↗

CWE-200

314
CRITICAL
1,854
HIGH
4,767
MEDIUM
614
LOW
7,697 CVEs · Page 15/154
5.5
CVE-2026-49219

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-

5.5
CVE-2026-32315

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Version

5.5
CVE-2026-33842

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-34328

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis

5.5
CVE-2026-34349

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in

5.5
CVE-2026-41087

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-50350

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authori

5.5
CVE-2026-50334

Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disc

5.5
CVE-2026-50339

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t

5.5
CVE-2026-50352

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack

5.5
CVE-2026-50389

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-50394

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in

5.5
CVE-2026-50409

Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to di

5.5
CVE-2026-50430

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t

5.5
CVE-2026-50431

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

5.5
CVE-2026-50434

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker t

5.5
CVE-2026-50442

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-50456

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-50473

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis

5.5
CVE-2026-50483

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker

5.5
CVE-2026-50681

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack

5.5
CVE-2026-56184

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose i

5.5
CVE-2026-49988

Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_

5.5
CVE-2026-47395

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso

5.5
CVE-2026-60607

Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: FM Need Analysis Ca

5.5
CVE-2026-17048

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w

5.5
CVE-2026-20672

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.

5.5
CVE-2026-43754

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.10 and iPadOS

5.5
CVE-2026-43756

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8,

5.5
CVE-2026-43758

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS

5.5
CVE-2026-43759

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.6, watchOS 26

5.5
CVE-2026-43782

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS T

5.5
CVE-2026-43796

This issue was addressed with improved data protection. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6

5.5
CVE-2026-43797

This issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadO

5.5
CVE-2026-43800

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iP

5.5
CVE-2026-43801

This issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadO

5.5
CVE-2026-64709

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 a

5.5
CVE-2026-64710

A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8

5.5
CVE-2026-64734

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS

5.5
CVE-2026-64741

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26

5.5
CVE-2026-64744

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,

5.5
CVE-2026-64755

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.

5.5
CVE-2026-17973

Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain

5.5
CVE-2026-54123

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attac

5.5
CVE-2026-64760

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10.

5.5
CVE-2026-16973

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an

5.5
CVE-2026-78957

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitiv

5.5
CVE-2026-79146

Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain

5.4
CVE-2025-68718

KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root crede

5.4
CVE-2026-20166

In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.1

Frequently Asked Questions

What is CWE-200?

CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-200?

There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.

How can I protect against CWE-200 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.

Detect CWE-200 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.

Get Started