FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition
The issue was addressed with improved memory handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensi
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerabi
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. Thi
Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header.
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configur
Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Informati
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected vers
Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Au
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home d
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
An information exposure vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows and MacOS where the
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Develop
Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user
SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege
IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure
Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_tok
The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies
EdgeX Foundry is an open source project for building a common open framework for Internet of Things edge computing. Prio
UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a nam
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication
Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use
Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 vers
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. A user in a privileged
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier,
NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not ha
NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not ha
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communica
Directory listing is a web server function that displays the directory contents when there is no index file in a specifi
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions <
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to acc
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticate
TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueBu
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mit
aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret wi
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypt
In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. T
Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multip
A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a l
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes
A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayF
A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Inform
A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw all
In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started