Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-52898 Frappe account takeover via password reset token leakage — frappe 9.1AICriticalAI2025-06-30
CVE-2025-49845 Discourse users are able to see their own whispers even after being removed from a group that has been configured to see whispers — discourse 4.3AIMediumAI2025-06-25
CVE-2025-39204 Hitachi MicroSCADA X SYS600 安全漏洞 — MicroSCADA X SYS600 6.5 Medium2025-06-24
CVE-2025-27387 OPPO Clone Phone uses weak WPA passphrase as only means of security — ColorOS 7.4 High2025-06-23
CVE-2025-52488 DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input — Dnn.Platform 8.6 High2025-06-21
CVE-2025-25037 Aquatronica Controller System Complete Information Disclosure — Aquatronica Controller System 9.8AICriticalAI2025-06-20
CVE-2025-52467 pgai secrets exfiltration via `pull_request_target` — pgai 9.1 Critical2025-06-19
CVE-2025-49593 Portainer HTTP Headers May Leak to Malicious Container Registries — portainer 6.8 Medium2025-06-17
CVE-2025-49824 conda-smithy Insecure Encryption Vulnerable to Oracle Padding Attack — conda-smithy 5.9AIMediumAI2025-06-17
CVE-2025-49177 Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: data leak in xfixes extension's xfixessetclientdisconnectmode — xwayland 6.1 Medium2025-06-17
CVE-2025-6199 Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder 3.3 Low2025-06-17
CVE-2025-49200 Unencrypted backup contains sensitive information — SICK Field Analytics 6.5 Medium2025-06-12
CVE-2025-49184 Information disclosure to unauthorized user — Field Analytics 7.5 High2025-06-12
CVE-2025-49150 Cursor Agent Potentially Leaks Information using JSON schema — cursor 5.9 Medium2025-06-11
CVE-2025-4798 WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Read — WP-DownloadManager 4.9 Medium2025-06-11
CVE-2025-30675 Apache CloudStack: Unauthorised template/ISO list access to the domain/resource admins — Apache CloudStack 4.7 Medium2025-06-10
CVE-2025-26521 Apache CloudStack: CKS cluster in project exposes user API keys — Apache CloudStack 7.5AIHighAI2025-06-10
CVE-2025-43579 Acrobat Reader | Information Exposure (CWE-200) — Acrobat Reader 5.5 Medium2025-06-10
CVE-2025-47969 Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability — Windows 11 version 22H2 4.4 Medium2025-06-10
CVE-2025-25250 Fortinet FortiOS 信息泄露漏洞 — FortiOS 3.9 Medium2025-06-10
CVE-2025-49143 Nautobot may allows uploaded media files to be accessible without authentication — nautobot 7.5AIHighAI2025-06-10
CVE-2024-38524 GWC Home Page communicate version and revision information — geoserver 5.3 Medium2025-06-10
CVE-2024-34711 GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF) — geoserver 9.3 Critical2025-06-10
CVE-2025-40662 Absolute path disclosure vulnerability in DM Corporative CMS — DM Corporative CMS 5.3AIMediumAI2025-06-10
CVE-2025-49653 Exposure of sensitive Information allows account takeover — BackendAI 8.0 High2025-06-09
CVE-2025-25209 Rhcl: sharedsecretref can be used to leak secrets severity 5.7 Medium2025-06-09
CVE-2025-47966 Power Automate Elevation of Privilege Vulnerability — Power Automate for Desktop 9.8 Critical2025-06-05
CVE-2025-5690 Cursor allows PostgreSQL Anonymizer masked user to gain unauthorized access to authentic data — PostgreSQL Anonymizer 6.5 Medium2025-06-04
CVE-2025-20129 Cisco Customer Collaboration Platform Information Disclosure Vulnerability — Cisco SocialMiner 4.3 Medium2025-06-04
CVE-2025-5436 Multilaser Sirius RE016 cstecgi.cgi information disclosure — Sirius RE016 5.3 Medium2025-06-02

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.