The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event regis
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp i
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh comma
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one the
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of anot
In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project
In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private pr
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's sy
sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to t
Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Of
Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Strategic Sourcin
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supporte
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Support
An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace informatio
IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage. IBM X-Force ID
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) generates an error message in error logs that includes sen
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Ma
Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for A
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking pol
A vulnerability in the packet processing code of Cisco IOS Software for Cisco Aironet Access Points could allow an unaut
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users rec
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being a
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unautho
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an
Microsoft Edge in Microsoft Windows 10 1703, 1709 and Windows Server, version 1709 allows an attacker to obtain informat
Microsoft Edge in Microsoft Windows 10 1703, 1709 and Windows Server, version 1709 allows an attacker to obtain informat
Internet Explorer in Microsoft Microsoft Windows 7 SP1, Windows Server 2008 SP2, Windows 8.1 and Windows RT 8.1, Windows
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participa
IBM Jazz technology based products might divulge information that might be useful in helping attackers through error mes
IBM Rhapsody DM products could reveal sensitive information in HTTP 500 Internal Server Error responses. IBM X-Force ID:
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacke
IBM Jazz Foundation products could allow an authenticated user to obtain sensitive information from stack traces. IBM X-
A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting infor
IBM Insights Foundation for Energy 2.0 could reveal sensitive information in error messages to authenticated users that
IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another use
IBM Jazz Foundation Products could disclose sensitive information during a scan that could lead to further attacks again
Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/s
IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount f
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent:
JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theore
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the syste
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another
The time subsystem in the Linux kernel through 4.9.9, when CONFIG_TIMER_STATS is enabled, allows local users to discover
The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be
Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect).
A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communica
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started