HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM
Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol
The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining
An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attack
A certain software build for the Orbic Maui device (Orbic/RC545L/RC545L:10/ORB545L_V1.4.2_BVZPP/230106:user/release-keys
Telemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthen
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue le
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundn
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability
An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feat
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned whil
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t
A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Le
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Le
In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of serv
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in mbbhatti Upload Resume.This issue affects Up
Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend develo
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in E4J s.R.L. VikRentCar.This issue affects Vik
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with
netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP r
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can acc
gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments t
Some parameters of the weather module are improperly stored, leaking some sensitive information.
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited
Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apa
Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the clie
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may a
nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to
MeterSphere is an open source continuous testing platform. Prior to version 2.10.14-lts, members without space permissio
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate th
ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of
System logs could be accessed through web management application due to a lack of access control. An attacker can obta
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo
ChargePoint Home Flex Bluetooth Low Energy Information Disclosure Vulnerability. This vulnerability allows network-adjac
In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2
MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privil
This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to ac
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sens
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Bi
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS V
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started