A vulnerability in Cisco Jabber software could allow an authenticated, remote attacker to gain access to sensitive infor
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticat
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of han
A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TC
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.
In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosu
The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to
Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect doma
In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from an
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard access in the lock
An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6700 before 1.0.1.26, R7000 b
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects R6400 before 1.0.1.2
: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attack
In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fi
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to info
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by d
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive
Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating th
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an attacker to obtain sensitive information due to insecure
In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would norm
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtu
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query paramet
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x vers
A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sen
An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Secur
An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointe
AgileBits 1Password through 1.0.9.340 allows security feature bypass
mysecureshell 1.31: Local Information Disclosure Vulnerability
An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Andro
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, whic
fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access t
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
An issue was discovered on Samsung mobile devices with N(7.x) (Exynos8890/8895 chipsets) software. There is information
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data struc
Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Com
IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects R6400v2 before 1.0.2
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6250 before V1.0.4.8, R6400 b
In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to ch
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a Q
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unau
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may pot
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain acc
IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started