Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-9196 Trinity Audio <= 5.21.0 - Unauthenticated Information Exposure — Trinity Audio – Text to Speech AI audio player to convert content into audio 5.3 Medium2025-10-11
CVE-2025-58278 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.2 Medium2025-10-11
CVE-2025-58277 Huawei HarmonyOS 安全漏洞 — HarmonyOS 4.0 Medium2025-10-11
CVE-2025-62158 Frappe had attachments made by students to their assignments of type Text set to public — lms 7.5AIHighAI2025-10-10
CVE-2025-61780 Rack has Possible Information Disclosure Vulnerability — rack 5.8 Medium2025-10-10
CVE-2025-52630 HCL AION is susceptible to Missing or insecure "X-Content-Type-Options" header vulnerability — AION 3.7 Low2025-10-10
CVE-2025-52634 HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed — HCL AION 3.7 Low2025-10-10
CVE-2025-10282 GitLab Domain Confusion in gitlab Leaks API Key — bbot 4.7 Medium2025-10-09
CVE-2025-10281 Insecure URL Handling in git_clone Leading to Leaked API Key — bbot 4.7 Medium2025-10-09
CVE-2025-61906 Opencast's editor accidentally publishes videos/overwrites publications #1626 — opencast 3.5AILowAI2025-10-08
CVE-2025-48464 Exposure of Sensitive Information — DuckDuckGo Browser 4.7 Medium2025-10-08
CVE-2025-11406 kaifangqian kaifangqian-base SysUserController.java getAllUsers information disclosure — kaifangqian-base 4.3 Medium2025-10-07
CVE-2025-61777 FlagForge Allows Unauthenticated Badge Template API Access — flagForge 9.4 Critical2025-10-06
CVE-2025-58589 Information Disclosure Through Stacktrace — Baggage Analytics 2.7 Low2025-10-06
CVE-2025-58581 Information Disclosure Through Stacktrace-/MQTT/Config/changeAll — Enterprise Analytics 4.3 Medium2025-10-06
CVE-2025-61679 Anyquery Unauthenticated Access Vulnerability Exposes Private Integration Data — anyquery 7.7 High2025-10-03
CVE-2025-9209 RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT — RestroPress – Online Food Ordering System 9.8 Critical2025-10-03
CVE-2025-61589 Cursor: Potential Information Leakage via Mermaid Diagram — cursor 5.9 Medium2025-10-03
CVE-2025-54468 Rancher sends sensitive information to external services through the `/meta/proxy` endpoint — rancher 4.7 Medium2025-10-02
CVE-2025-40645 Exposure of sensitive information in Viday — ViDay 7.5AIHighAI2025-10-02
CVE-2025-54290 Project Existence Disclosure via Error Handling in LXD Image Export — LXD 5.3AIMediumAI2025-10-02
CVE-2025-10744 File Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information Exposure — File Manager, Code Editor, and Backup by Managefy 5.9 Medium2025-10-01
CVE-2025-8868 Chef Automate compliance service SQL Injection Vulnerability — Chef Automate 9.8 Critical2025-09-29
CVE-2025-11028 givanz Vvveb Image information disclosure — Vvveb 5.3 Medium2025-09-26
CVE-2025-11026 givanz Vvveb Configuration File information disclosure — Vvveb 3.5 Low2025-09-26
CVE-2025-10952 geyang ml-logger File server.py stream_handler information disclosure — ml-logger 5.3 Medium2025-09-25
CVE-2025-36601 Dell PowerScale OneFS 信息泄露漏洞 — PowerScale OneFS 4.0 Medium2025-09-25
CVE-2025-59833 FlagForgeCTF Hint Exposure via API — flagForge 7.5 High2025-09-24
CVE-2025-59434 Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript Function — Flowise 9.6 Critical2025-09-22
CVE-2025-59427 Cloudflare vite plugin exposes secrets over the built-in dev server — workers-sdk 5.5 -2025-09-19

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.