In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discoverin
An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. T
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to
In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified at
HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processo
A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log file
A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker ca
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could a
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get f
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change p
On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets desti
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). An attacker with network access t
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab
An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadyS
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticat
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST int
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si
An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides
Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciou
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messa
Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some
The issue was addressed by removing origin information. This issue affected versions prior to iOS 12, watchOS 5, Safari
An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler fram
In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command lin
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinf
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be p
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resou
In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosur
In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. Thi
In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improv
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access cont
An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a
An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.
A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could al
In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/v
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started