HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard
An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memor
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-c
In Euicc, there is a possible information disclosure due to an included test Certificate. This could lead to remote info
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted reques
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, an attacker ca
Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 20
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is information disclosure of th
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos or Qualcomm chipsets) software
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard content visibility
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is a Keyboard learned words lea
An issue was discovered on Samsung mobile devices with N(7.x) (MediaTek chipsets) software. There is information disclos
GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQU
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 be
The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulner
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7000 before 1.0.1.52, D7800 b
Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-0
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames a
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create speci
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridgin
IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to info
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not con
An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstra
SSB-DB version 20.0.0 has an information disclosure vulnerability. The get() method is supposed to only decrypt messages
A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an at
A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allo
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal informati
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web site
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthen
A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inje
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker access to sensitive informat
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessm
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high
NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application s
A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or Whats
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to ac
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challeng
Visual Components (owned by KUKA) is a robotic simulator that allows simulating factories and robots in order toimprove
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Pa
A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensit
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?to
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started