An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail addr
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive inf
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team inv
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invit
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about tea
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amaz
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view
Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and othe
In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The proble
This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "
IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in furt
IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclo
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP8). If configured in an insecure manner,
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as d
The participants table download in Moodle always included user emails, but should have only done so when users' emails a
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclo
Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This aff
A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release in
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be dis
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submissi
In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to displa
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prio
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and
In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification cont
A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a leg
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative
A vulnerability in the CLI of Cisco Network Services Orchestrator (NSO) could allow an authenticated, local attacker to
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Attackers can bypass Factory Reset Pr
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is Clipboard access in
An issue was discovered on Samsung mobile devices with O(8.x) software. The Smartwatch displays Secure Folder Notificati
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D6220 before 1.0.0.4
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D3600 before 1.0.0.76 and D600
Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the
Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in
QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obta
Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data
A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to r
A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop A
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vuln
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterCons
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrec
An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which cou
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webm
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started