A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a loc
Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
An attacker can use the unrestricted LDAP queries to determine configuration entries
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <
Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attack
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function m
Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multip
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary
Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G
Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged us
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the da
PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://'
Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache ShardingSphere ElasticJob-UI allows a
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`,
S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Ro
Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed s
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default config
HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently sto
Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticate
sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that u
Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof d
Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having t
DisCatSharp is a Discord API wrapper for .NET. Users of versions 9.8.5, 9.8.6, 9.9.0 and previously published prerelease
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password b
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to acce
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-b
RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosu
Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon In
IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a
Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows a
Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitiv
Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access s
The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preve
fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Version
An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server meth
Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privileg
Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user o
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, and 1.42.6, it was po
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started