GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vec
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the
A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage,
Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identific
An issue was discovered on Samsung mobile devices with M(6.0) software. Because of an unprotected intent, an attacker ca
Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere.
An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms
Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when t
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to ful
An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may all
DOMPDF before 0.6.2 allows Information Disclosure.
An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Conne
The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive inf
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote auth
Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive infor
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a mali
Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote aut
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discover
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the app
In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secre
NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials.
NETGEAR GS810EMX devices before 1.0.0.5 are affected by disclosure of sensitive information.
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects DST6501 before 1.1.0
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects EX3700 before 1.0.0.
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC505 before 5.0.0.17 and WAC
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.2
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.2
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.3
Percona XtraBackup before 2.4.20 unintentionally writes the command line to any resulting backup file output. This may i
Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job de
ZTE SDN controller platform is impacted by an information leakage vulnerability. Due to the program's failure to optimiz
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RAD
Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and oth
An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive informati
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged networ
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Informati
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started