Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-7041 666ghj MiroFish Werkzeug Debugger PIN console information disclosure — MiroFish 3.7 Low2026-04-26
CVE-2026-7021 SmythOS sre Connector Service utils.ts information disclosure — sre 3.5 Low2026-04-26
CVE-2026-41492 Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in Dgraph — dgraph 9.8 Critical2026-04-24
CVE-2026-21515 Azure IoT Central Elevation of Privilege Vulnerability — Azure IOT Central 9.9 Critical2026-04-24
CVE-2026-41323 Kyverno: ServiceAccount token leaked to external servers via apiCall service URL — kyverno 8.1 High2026-04-24
CVE-2026-41278 Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs — Flowise 7.5AIHighAI2026-04-23
CVE-2026-41266 Flowise: Sensitive Data Leak in public-chatbotConfig — Flowise 9.1AICriticalAI2026-04-23
CVE-2026-41182 LangSmith SDK: Streaming token events bypass output redaction — langsmith-sdk 5.3 Medium2026-04-23
CVE-2026-4126 Table Manager <= 1.0.0 - Authenticated (Contributor+) Sensitive Information Exposure via 'table' Shortcode Attribute — Table Manager 4.3 Medium2026-04-22
CVE-2026-6392 Tanium addressed an information disclosure vulnerability in Threat Response. — Threat Response 2.7 Low2026-04-22
CVE-2026-40895 follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets — follow-redirects 6.1AIMediumAI2026-04-21
CVE-2026-40908 WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php that Exposes Developer Emails and Deployed Version — AVideo 5.3 Medium2026-04-21
CVE-2026-40885 goshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized access — goshs 9.1AICriticalAI2026-04-21
CVE-2026-40584 RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information Exposure — RansomLook 5.3AIMediumAI2026-04-21
CVE-2026-41183 FreeScout allows non-folder conversation queries to disclose assigned-only hidden conversations — freescout 4.3 Medium2026-04-21
CVE-2026-40498 FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron — freescout 9.1AICriticalAI2026-04-21
CVE-2026-34839 Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS — glances 6.5AIMediumAI2026-04-20
CVE-2026-40490 AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects — async-http-client 6.8 Medium2026-04-18
CVE-2026-2262 Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST API — Easy Appointments 7.5 High2026-04-17
CVE-2026-40293 OpenFGA Playground Preshared Key Exposure — openfga 6.5 Medium2026-04-17
CVE-2025-65104 Firebird: Information leak vulnerability in firebird3 client when used with newer server — firebird 7.9 High2026-04-17
CVE-2026-6492 arnobt78 Hotel Booking Management System Health Check Endpoint detailed information disclosure — Hotel Booking Management System 5.3 Medium2026-04-17
CVE-2026-23777 Dell PowerProtect Data Domain 安全漏洞 — PowerProtect Data Domain 4.3 Medium2026-04-17
CVE-2026-40245 Free5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication — free5gc 7.5 High2026-04-15
CVE-2026-40173 Dgraph: Unauthenticated pprof endpoint leaks admin auth token — dgraph 9.4 Critical2026-04-15
CVE-2026-39857 Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions — apostrophe 5.3 Medium2026-04-15
CVE-2026-34244 Weblate: SSRF via Project-Level Machinery Configuration — weblate 5.0 Medium2026-04-15
CVE-2026-32631 Git for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary servers — git 7.4 High2026-04-15
CVE-2025-12141 Grafana Alerting Editors can edit destination of webhooks they did not create — Grafana Alerting 8.1 -2026-04-15
CVE-2026-25219 Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access — Apache Airflow 6.5 -2026-04-15

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.