There is an information disclosure vulnerability in several smartphones. The system has a logic judging error under cert
An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.2 and iPadOS 16
vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configure
This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14
This issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Note
HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot
The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17,
This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7
There is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the
HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application d
A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affect
Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemer
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an
Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast i
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an
symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources s
Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor
In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a
Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resource
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vuln
A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to g
Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Onli
An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior
Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share li
This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical acc
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical acc
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported versi
Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is
Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log
Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenText Performance Center on Windows allow
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modul
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTri
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vul
Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a
matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starti
A publish-access account was compromised for `@solana/web3.js`, a JavaScript library that is commonly used by Solana dap
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWE
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started