A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remo
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observabilit
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. Th
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.33.2 is vulnerable to a side-channel
In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if
IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive in
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects EAX80 before 1.0.1.62, EX7000
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads var
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was id
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel inform
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker
Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Acce
Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial nu
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predic
Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9
This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a
In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installe
@sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform
Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to inform
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an au
A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firep
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or a
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_u
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.
Local privilege escalation in admin services in Windows environment can occur due to an arbitrary read issue.
HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information e
Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of
A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitima
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information t
An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionar
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identi
IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trac
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensiti
IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sens
pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated
express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration opt
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions befor
Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where runni
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started