Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination s
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (
yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external down
Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes. Prior to version 0.3.0, ironic an
IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information
IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to information Disclosure due to improper privile
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain secu
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.
IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a downl
IBM PowerVM Hypervisor FW950.00 through FW950.71, FW1010.00 through FW1010.40, FW1020.00 through FW1020.20, and FW1030.0
The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud ver
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or pro
An Exposure of Sensitive Information vulnerability in the 'file copy' command of Junos OS Evolved allows a local, authen
The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.
Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may all
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orde
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orde
TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgst
Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get acce
A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privilege
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions start
OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implem
Metabase is an open source data analytics platform. Affected versions are subject to Exposure of Sensitive Information t
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user dat
When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when access
Design document functions which receive a user http request object may expose authorization or session cookie headers of
A session rendering issue was addressed with improved session tracking. This issue is fixed in macOS Sonoma 14.2.1. A us
A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access
In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local atta
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijac
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting fro
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additi
A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey
The issue was addressed with improved memory handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadO
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. A
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2,
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started