Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-30291 ColdFusion | Information Exposure (CWE-200) — ColdFusion 5.5 Medium2025-04-08
CVE-2025-29805 Outlook for Android Information Disclosure Vulnerability — Microsoft Outlook for Android 7.5 High2025-04-08
CVE-2025-27736 Windows Power Dependency Coordinator Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2025-04-08
CVE-2025-26667 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability — Windows Server 2008 R2 Service Pack 1 6.5 Medium2025-04-08
CVE-2025-2883 Accept SagePay Payments Using Contact Form 7 <= 2.0 - Unauthenticated Information Exposure — Accept SagePay Payments Using Contact Form 7 5.3 Medium2025-04-08
CVE-2025-2882 GreenPay(tm) by Green.Money 3.0.0 - 3.0.9 - Unauthenticated Information Exposure — GreenPay(tm) by Green.Money 5.3 Medium2025-04-08
CVE-2024-13820 Melhor Envio <= 2.15.11 - Unauthenticated Sensitive Information Exposure via Hardcoded Hash — Melhor Envio 5.3 Medium2025-04-08
CVE-2024-43046 Information Exposure in TZ Secure OS — Snapdragon 5.5 Medium2025-04-07
CVE-2025-31492 mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data — mod_auth_openidc 7.5AIHighAI2025-04-06
CVE-2024-13604 KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin 7.5 High2025-04-05
CVE-2024-42208 HCL Connections is vulnerable to an information disclosure vulnerability — HCL Connections 3.5 Low2025-04-04
CVE-2025-31486 Vite allows server.fs.deny to be bypassed with .svg or relative paths — vite 5.3 Medium2025-04-03
CVE-2025-31126 Element X iOS allows the entity in control of the well-known file to break the confidentiality of embedded Element Call — element-x-ios 5.3 Medium2025-04-03
CVE-2025-31127 Element X Android allows the entity in control of the well-known file to break the confidentiality embedded Element Call — element-x-android 5.3 Medium2025-04-03
CVE-2025-30218 Next.js may leak x-middleware-subrequest-id to external hosts — next.js 7.5AIHighAI2025-04-02
CVE-2025-2842 Tempo-operator: tempo operator token exposition lead to read sensitive data 4.3 Medium2025-04-02
CVE-2025-2786 Tempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operator 4.3 Medium2025-04-02
CVE-2025-30224 MyDumper arbitrary file read issue — mydumper 6.5AIMediumAI2025-04-01
CVE-2024-13567 Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Awesome Support – WordPress HelpDesk & Support Plugin 7.5 High2025-04-01
CVE-2025-31125 Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query — vite 5.3 Medium2025-03-31
CVE-2025-2840 DAP to Autoresponders Email Syncing <= 1.0 - Unauthenticated Information Exposure — DAP to Autoresponders Email Syncing 5.3 Medium2025-03-29
CVE-2025-2860 Exposure of Sensitive Information vulnerability in saTECH BCU — saTECH BCU 6.5 -2025-03-28
CVE-2021-24008 Fortinet多款产品 信息泄露漏洞 — FortiDDoS 5.0 Medium2025-03-28
CVE-2025-2578 Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure — Booking for Appointments and Events Calendar – Amelia 5.3 Medium2025-03-28
CVE-2025-20232 Risky Command Safeguards Bypass in “/app/search/search“ endpoint through “s“ parameter in Splunk Enterprise — Splunk Enterprise 5.7 Medium2025-03-26
CVE-2025-20226 Risky command safeguards bypass in “/services/streams/search“ endpoint through “q“ parameter in Splunk Enterprise — Splunk Enterprise 5.7 Medium2025-03-26
CVE-2025-30353 Directus's webhook trigger flows can leak sensitive data — directus 8.6 High2025-03-26
CVE-2025-30352 Directus `search` query parameter allows enumeration of non permitted fields — directus 5.3 Medium2025-03-26
CVE-2025-23203 Icinga has rest API endpoints accessible to restricted users — icingaweb2-module-director 5.5 Medium2025-03-26
CVE-2025-2228 Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates <= 1.6.8 - Authenticated (Contributor+) Sensitive Information Exposure — Responsive Addons for Elementor – Free Elementor Addons, Kits and Elementor Templates 5.7 Medium2025-03-26

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.