Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 ar
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An atta
A vulnerability in Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, local attacker to obt
The modprobe child process in the ./debian/patches/load_ppp_generic_if_needed patch file incorrectly handled module load
u'Information disclosure issue can occur due to partial secure display-touch session tear-down' in Snapdragon Auto, Snap
u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display s
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by readin
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI d
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser his
GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.
GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.
An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control me
When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal r
IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used t
Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent pu
mIRC prior to 7.22 has a message leak because chopping of outbound messages is mishandled.
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E
An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attac
An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processin
Verax NMS prior to 2.1.0 leaks connection details when any user executes a Repair Table action
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attacker
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to ob
IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if una
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthent
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was uni
In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOT
IBM Content Navigator 3.0CD could disclose sensitive information to an unauthenticated user which could be used to aid i
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks a thumbnail of Private
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's A
An issue was discovered on Samsung mobile devices with software through 2016-10-25 (Exynos5 chipsets). Attackers can rea
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) software. Contact information can leak to a log
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. An attacker can
An issue was discovered on Samsung mobile devices with M(6.0) software. There is an information disclosure in a Trustlet
Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discov
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Exposure of Sensi
IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability. The SNMPv2 services is enabled, by def
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by v
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote
A specially crafted request could be used to confirm the existence of files hosted on object storage services, without d
A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated,
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started