Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14528 D-Link DIR-803 Configuration getcfg.php information disclosure — DIR-803 5.3 Medium2025-12-11
CVE-2025-67499 CNI Plugins Portmap nftables backend intercepts non-local traffic — plugins 6.6 Medium2025-12-09
CVE-2025-66625 Umbraco Vulnerable to Improper File Access and Credential Exposure through Dictionary Import Functionality — Umbraco-CMS 4.9 Medium2025-12-09
CVE-2025-64670 Windows DirectX Information Disclosure Vulnerability — Windows 10 Version 21H2 6.5 Medium2025-12-09
CVE-2024-38798 Uncleared password keystrokes in circular queue can lead to information disclosure or escalation of privilege — EDK2 7.8AIHighAI2025-12-09
CVE-2025-12558 Beaver Builder – WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure — Beaver Builder Page Builder – Drag and Drop Website Builder 4.3 Medium2025-12-09
CVE-2025-40941 Siemens SIMATIC CN 4100 信息泄露漏洞 — SIMATIC CN 4100 4.3 Medium2025-12-09
CVE-2025-40940 Siemens SIMATIC CN 4100 信息泄露漏洞 — SIMATIC CN 4100 4.9 Medium2025-12-09
CVE-2025-14286 Tenda AC9 Configuration File DownloadCfg.jpg information disclosure — AC9 5.3 Medium2025-12-09
CVE-2025-66330 Huawei HarmonyOS 安全漏洞 — HarmonyOS 4.9 Medium2025-12-08
CVE-2025-58279 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 4.4 Medium2025-12-08
CVE-2025-14198 Verysync 微力同步 Web Administration download information disclosure — 微力同步 5.3 Medium2025-12-07
CVE-2025-14197 Verysync 微力同步 Web Administration f96956469e7be39d information disclosure — 微力同步 5.3 Medium2025-12-07
CVE-2025-66623 Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands — strimzi-kafka-operator 7.4 High2025-12-05
CVE-2025-13006 SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure — SurveyFunnel – Survey Plugin for WordPress 5.3 Medium2025-12-05
CVE-2025-13494 SSP Debug <= 1.0.0 - Unauthenticated Sensitive Information Exposure — SSP Debug 5.3 Medium2025-12-05
CVE-2025-10285 Simplcity Device Manager exposes NTLMv2 hash — Simplicity Studio V6 7.5AIHighAI2025-12-04
CVE-2025-11379 WebP Express <= 0.25.9 - Unauthenticated Information Exposure — WebP Express 5.3 Medium2025-12-04
CVE-2025-20383 Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app — Splunk Enterprise 4.3 Medium2025-12-03
CVE-2025-12585 MxChat – AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure — MxChat – AI Chatbot & Content Generation for WordPress 5.3 Medium2025-12-03
CVE-2025-41066 Disclosure of sensitive information in Horde Groupware — Groupware 5.3AIMediumAI2025-12-02
CVE-2025-41015 User Enumeration vulnerability in TCMAN GIM — GIM 5.3AIMediumAI2025-12-02
CVE-2025-41014 User Enumeration vulnerability in TCMAN GIM — GIM 5.3AIMediumAI2025-12-02
CVE-2025-13696 Zigaform <= 7.6.5 - Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint — Zigaform – Price Calculator & Cost Estimation Form Builder Lite 5.3 Medium2025-12-02
CVE-2025-66304 Grav Exposes Password Hashes Leading to privilege escalation — grav 6.2 Medium2025-12-01
CVE-2025-13653 Unauthorized access to documents in data streams with specially crafted requests — Search Guard FLX 4.3 Medium2025-12-01
CVE-2025-2879 Mali GPU Kernel Driver allows improper GPU processing operations — Valhall GPU Kernel Driver 5.5AIMediumAI2025-12-01
CVE-2025-13804 nutzam NutzBoot Ethereum Wallet EthModule.java information disclosure — NutzBoot 4.3 Medium2025-12-01
CVE-2025-13785 yungifez Skuul School Management System Image profile information disclosure — Skuul School Management System 4.3 Medium2025-11-30
CVE-2025-66027 Rallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy Settings — rallly 4.3 -2025-11-29

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.