A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow
An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed t
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed t
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8. A customer user can use the search res
arxes-tolina 3.0.0 allows User Enumeration.
For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application.
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R8300 before 1.0.2.106 and R85
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for acc
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had
Centreon before 19.10.7 exposes Session IDs in server responses.
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables atta
An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web br
IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by disclosing private IP addres
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote,
An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA)
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vul
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sen
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jir
A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show th
Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as
Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all referenc
Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argum
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-v
An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local
Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or re
When in maintenance mode, Magento version 2.4.0 and 2.3.4 (and earlier) are affected by an information disclosure vulner
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP add
BCC recipients in mails sent from OTRS are visible in article detail on external interface. This issue affects OTRS: 8.0
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating syste
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploa
An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caus
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak console
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is infor
An issue was discovered on Samsung mobile devices with M(6.x) (Exynos or Qualcomm chipsets) software. There is informati
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is
An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially c
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correct
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. The module controller in `SimpleSA
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent dur
The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue af
An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximat
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) (Galaxy S9+, Galaxy S9, Galaxy S8+, Galaxy S8,
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is a Clipboard content
In the WifiConfigManager, there is a possible storage of location history which can only be deleted by triggering a fact
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started