The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sen
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attac
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sens
The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive in
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sen
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sens
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacke
mediawiki allows deleted text to be exposed
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, whic
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, whic
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium ,
MiniUPnPd has information disclosure use of snprintf()
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
Cryptocat strophe.js before 2.0.22 has information disclosure
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
Dump Servlet information leak in jetty before 6.1.22.
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read inter
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about th
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which a
Moodle has a database activity export permission issue where the export function of the database activity module exports
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web inter
ClamAV before 0.97.7: dbg_printhex possible information leak
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.i
mpack 1.6 has information disclosure via eavesdropping on mails sent by other users
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers t
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x be
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Prem
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2)
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of d
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download th
gnome-system-log polkit policy allows arbitrary files on the system to be read
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature prov
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to in
Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain no
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info
An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle o
SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to con
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker c
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker c
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS 12.2. A device may
A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in iOS 12.3, tvOS 12.3, wa
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacke
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provid
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-
Frequently Asked Questions
What is CWE-200?
CWE-200 (CWE-200) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-200?
There are 11,142 CVE records associated with CWE-200 in our database. Of these, 314 are critical severity, 1854 are high severity, and 4767 are medium severity.
How can I protect against CWE-200 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-200 using AI-powered security agents.
Detect CWE-200 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-200 vulnerabilities across your infrastructure.
Get Started