Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-62206 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.1 6.5 Medium2025-11-11
CVE-2025-11697 Studio 5000 ® Simulation Interface Local Code Execution — Studio 5000 ® Simulation Interface 7.8 -2025-11-11
CVE-2025-11997 Document Pro Elementor – Documentation & Knowledge Base <= 1.0.9 - Unauthenticated Information Exposure — Document Pro Elementor – Documentation & Knowledge Base 5.3 Medium2025-11-11
CVE-2025-12010 Authors List <= 2.0.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Limited Method Call in Plugin's Shortcode — Authors List 6.5 Medium2025-11-11
CVE-2025-12098 Academy LMS Pro <= 3.3.8 - Unauthenticated Sensitive Information Exposure via 'enqueue_social_login_script' — Academy LMS Pro 5.3 Medium2025-11-08
CVE-2025-20377 Cisco Unified Intelligence Center API Information Disclosure Vulnerability — Cisco Packaged Contact Center Enterprise 4.3 Medium2025-11-05
CVE-2025-12468 FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure — FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce 5.3 Medium2025-11-05
CVE-2025-12677 KiotViet Sync <= 1.8.5 - Unauthenticated Webhook Key Exposure — KiotViet Sync 5.3 Medium2025-11-05
CVE-2025-12139 File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure — File Manager for Google Drive – Integrate Google Drive 7.5 High2025-11-05
CVE-2025-11749 AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation — AI Engine – The Chatbot, AI Framework & MCP for WordPress 9.8 Critical2025-11-05
CVE-2025-62721 LinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and Tags — LinkAce 4.3AIMediumAI2025-11-04
CVE-2025-62720 LinkAce: Data Exfiltration via Export Functions Allow Access to All Users' Private Links — LinkAce 4.3AIMediumAI2025-11-04
CVE-2025-11983 WP Discourse <= 2.5.9 - Authenticated (Author+) Information Exposure — WP Discourse 4.3 Medium2025-11-01
CVE-2025-11377 List category posts <= 0.92.0 - Authenticated (Contributor+) Information Exposure — List category posts 4.3 Medium2025-11-01
CVE-2025-12521 Analytify Pro <= 7.0.3 - Unauthenticated Information Exposure — Analytify Pro 5.3 Medium2025-10-31
CVE-2025-34272 Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback — Log Server 9.1AICriticalAI2025-10-30
CVE-2025-11998 HP Card Readers (B Models) – Potential Information Disclosure — Card Readers B Model 5.3AIMediumAI2025-10-30
CVE-2025-54548 On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes) — DANZ Monitoring Fabric 4.3 Medium2025-10-29
CVE-2025-11203 LiteLLM Information health API_KEY Information Disclosure Vulnerability — LiteLLM 6.5AIMediumAI2025-10-29
CVE-2025-12148 Unauthorized access to fields protected by Field Masking (FM) for fields of type IP — Search Guard FLX 9.1AICriticalAI2025-10-29
CVE-2025-12147 Unauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an object — Search Guard FLX 9.1AICriticalAI2025-10-29
CVE-2023-7320 WooCommerce <= 7.8.2 - Sensitive Information Exposure — WooCommerce 5.3 Medium2025-10-29
CVE-2025-62524 PILOS Exposes PHP version — PILOS 5.3 Medium2025-10-27
CVE-2025-12363 Email Password Disclosure — BLU-IC2 6.5AIMediumAI2025-10-27
CVE-2025-12297 atjiu pybbs UserApiController.java information disclosure — pybbs 4.3 Medium2025-10-27
CVE-2025-12276 LearnHouse Image information disclosure — LearnHouse 4.3 Medium2025-10-27
CVE-2025-11760 eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information Exposure — eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams 5.3 Medium2025-10-25
CVE-2025-6980 Captive Portal can expose sensitive information — Arista Edge Threat Management - Arista Next Generation Firewall 7.5 High2025-10-23
CVE-2025-62400 Moodle: hidden group names visible to event creators 4.3 Medium2025-10-23
CVE-2025-62604 MeterSphere logic flaw allows retrieval of arbitrary user information — metersphere 7.5AIHighAI2025-10-22

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.