Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-4222 Database Toolset <= 1.8.4 - Unauthenticated Sensitive Information Exposure via Backup Files — Database Toolset 5.9 Medium2025-05-03
CVE-2025-46332 Information Disclosure via Flags override link — flags 6.5 Medium2025-05-02
CVE-2025-2880 Yame | Link In Bio <= 0.9.0 - Unauthenticated Information Exposure — Yame | Link In Bio 5.3 Medium2025-05-02
CVE-2024-11994 APM Server Insertion of Sensitive Information into Log File — APM Server 5.7 Medium2025-05-01
CVE-2023-46669 Elastic Agent / Elastic Endpoint Security local API key disclosure — Elastic Agent and Elastic Defend 6.2 Medium2025-05-01
CVE-2025-46552 KHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation Automation — KHC-INVITATION-AUTOMATION 5.3AIMediumAI2025-04-29
CVE-2025-3978 dazhouda lecms user_set.htm information disclosure — lecms 4.3 Medium2025-04-27
CVE-2025-3975 ScriptAndTools eCommerce-website-in-PHP subscriber-csv.php information disclosure — eCommerce-website-in-PHP 5.3 Medium2025-04-27
CVE-2025-3966 itwanger paicoding Browsing History home information disclosure — paicoding 4.3 Medium2025-04-27
CVE-2025-32044 Moodle: unauthenticated rest api user data exposure 7.5 High2025-04-25
CVE-2025-3628 Moodle: moodle assignment submission search leaks anonymous student identities 4.3 Medium2025-04-25
CVE-2025-3923 Prevent Direct Access – Protect WordPress Files <= 2.8.8 - Unauthenticated Sensitive Information Exposure — Prevent Direct Access – Protect WordPress Files 5.3 Medium2025-04-25
CVE-2024-11299 Memberpress <= 1.11.37 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Memberpress 5.3 Medium2025-04-22
CVE-2025-32958 Adept exposed the GITHUB_TOKEN in workflow run artifact — Adept 9.8 Critical2025-04-21
CVE-2025-23174 Yoel Geva - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — Android App 7.5 High2025-04-21
CVE-2025-32953 z80pack Vulnerable to Exposure of the GITHUB_TOKEN in Workflow Run Artifact — z80pack 8.7 High2025-04-18
CVE-2025-32789 EspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting Function — espocrm 3.1 Low2025-04-16
CVE-2025-3104 WP Staging Pro <= 6.1.2 - Unauthenticated Information Exposure via getOutdatedPluginsRequest Function — WP STAGING Pro WordPress Backup Plugin 5.3 Medium2025-04-16
CVE-2025-31494 AutoGPT allows cross-user sharing of node execution results through WebSockets API — AutoGPT 3.5 Low2025-04-14
CVE-2025-31491 AutoGPT allows leakage of cross-domain cookies and protected headers in requests redirect — AutoGPT 8.6 High2025-04-14
CVE-2025-2881 Developer Toolbar <= 1.0.3 - Unauthenticated Information Exposure — Developer Toolbar 5.3 Medium2025-04-12
CVE-2025-2841 Cart66 Cloud <= 2.3.7 - Unauthenticated Information Exposure — Cart66 Cloud :: WordPress Ecommerce The Easy Way 5.3 Medium2025-04-12
CVE-2025-32080 Cross-origin data leak in mobilefrontend via lazy load images — Mediawiki - Mobile Frontend Extension 5.3AIMediumAI2025-04-11
CVE-2024-52280 Users can issue watch commands for arbitrary resources — rancher 7.7 High2025-04-11
CVE-2024-52282 Rancher Helm Applications may have sensitive values leaked — rancher 6.2 Medium2025-04-11
CVE-2025-23387 Rancher's SAML-based login via CLI can be denied by unauthenticated users — rancher 5.3 Medium2025-04-11
CVE-2025-32700 AbuseFilter log interfaces expose global private and hidden filters when central DB is not available — MediaWiki 7.5AIHighAI2025-04-10
CVE-2025-32698 LogPager.php: Restriction enforcer functions do not correctly enforce suppression restrictions — MediaWiki 7.5AIHighAI2025-04-10
CVE-2025-32395 Vite has an `server.fs.deny` bypass with an invalid `request-target` — vite 7.5AIHighAI2025-04-10
CVE-2025-30654 Junos OS and Junos OS Evolved: A local, low privileged user can access sensitive information — Junos OS 5.5 Medium2025-04-09

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.