A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Se
OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernete
In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing perm
In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic er
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorize
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose i
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an author
A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPad
The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentio
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 26.1 and iPadOS 26.1
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1
A privacy issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, v
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonom
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to
This issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.
This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe
This issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.
An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in
The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to
The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4,
An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via
Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in Gmission Web Fax allo
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially
Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information a
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 2
A vulnerability was found in Provision-ISR SH-4050A-2, SH-4100A-2L(MM), SH-8100A-2L(MM), SH-16200A-2(1U), SH-16200A-5(1U
The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ
The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Inform
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure i
A vulnerability, which was classified as problematic, has been found in 1902756969 reggie 1.0. Affected by this issue is
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.
A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the
Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above
The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.
Nuxt is an open-source web development framework for Vue.js. Starting in version 3.8.1 and prior to version 3.15.3, Nuxt
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started