The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2,
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead
Microsoft OneDrive for Android Information Disclosure Vulnerability
Microsoft OneDrive for Android Information Disclosure Vulnerability
A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin befo
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown pre
An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.1
Windows Kernel Memory Information Disclosure Vulnerability
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification
Windows Cryptographic Information Disclosure Vulnerability
The issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able t
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information D
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning
Sensitive information disclosure due to excessive collection of system information. The following products are affected:
A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys bein
On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS
A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, Forti
msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained t
microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which cont
A vulnerability classified as problematic has been found in ethitter WP-Print-Friendly up to 0.5.2. This affects an unkn
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 3.0.0.beta
A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vul
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions start
Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default admi
In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension ca
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen
Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and 3.1.0.beta2 on the `b
A vulnerability, which was classified as critical, was found in Multilaser RE057 and RE170 2.1/2.2. This affects an unkn
A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part o
An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial E
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclos
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active sessio
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a det
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious ap
Discourse is an open source platform for community discussion. Tags that are normally private are showing in metadata. T
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and in
Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed mes
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardw
A sensitive information disclosure vulnerability in GitLab affecting all versions from 15.0 prior to 15.8.5, 15.9 prior
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of a
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connec
An issue in Teslamate v1.27.1 allows attackers to obtain sensitive information via directly accessing the teslamate link
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started