Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-30222 Shescape has potential environment variable exposure on Windows with CMD — shescape 7.5AIHighAI2025-03-25
CVE-2025-30214 Frappe vulnerable to information disclosure leading to account takeover — frappe 8.1AIHighAI2025-03-25
CVE-2025-2252 Easy Digital Downloads – eCommerce Payments and Subscriptions made easy <= 3.3.6.1 - Unauthenticated Private Post Title Disclosure — Easy Digital Downloads – eCommerce Payments and Subscriptions made easy 5.3 Medium2025-03-25
CVE-2025-30208 Vite bypasses server.fs.deny when using `?raw??` — vite 5.3 Medium2025-03-24
CVE-2025-30474 Apache Commons VFS: Failing to find an FTP file can reveal the URI's password in an error message — Apache Commons VFS 7.5 -2025-03-23
CVE-2025-2331 GiveWP – Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure — GiveWP – Donation Plugin and Fundraising Platform 5.3 Medium2025-03-22
CVE-2025-27784 Applio allows arbitrary file read in train.py export_pth function — Applio 7.5 -2025-03-19
CVE-2025-27785 Applio allows arbitrary file read in train.py export_index function — Applio 7.5 -2025-03-19
CVE-2025-26485 Beta80 Life 1st 安全漏洞 — Life 1st 5.8 Medium2025-03-19
CVE-2025-29781 Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD — baremetal-operator 6.5 Medium2025-03-17
CVE-2020-29010 FortiGate 安全漏洞 — FortiOS 4.9 Medium2025-03-17
CVE-2025-2348 IROAD Dash Cam FX2 HTTP/RTSP event information disclosure — Dash Cam FX2 4.3 Medium2025-03-16
CVE-2025-1636 Devolutions Remote Desktop Manager 安全漏洞 — Remote Desktop Manager 6.5 -2025-03-13
CVE-2025-1635 Devolutions Remote Desktop Manager 安全漏洞 — Remote Desktop Manager 6.5 -2025-03-13
CVE-2025-2277 Devolutions Server 安全漏洞 — Server 6.5 -2025-03-13
CVE-2024-13498 NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure — NEX-Forms – Ultimate Forms Plugin for WordPress 5.3 Medium2025-03-12
CVE-2025-24071 Microsoft Windows File Explorer Spoofing Vulnerability — Windows 10 Version 1507 6.5 Medium2025-03-11
CVE-2023-40723 Fortinet FortiSIEM 信息泄露漏洞 — FortiSIEM 7.7 High2025-03-11
CVE-2025-27615 umatiGateway's UI publicly accessible in provided docker-compose file — umatiGateway 8.2 High2025-03-10
CVE-2025-1322 WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post Disclosure — WP-Recall – Registration, Profile, Commerce & More 4.3 Medium2025-03-08
CVE-2024-10321 All-in-One Addons for Elementor – WidgetKit <= 2.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates — All-in-One Addons for Elementor – WidgetKit 4.3 Medium2025-03-08
CVE-2024-13640 Print Invoice & Delivery Notes for WooCommerce <= 5.4.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Print Invoice & Delivery Notes for WooCommerce 5.9 Medium2025-03-08
CVE-2024-13086 QTS, QuTS hero — QTS 5.3 Medium2025-03-07
CVE-2025-27604 XWiki Confluence Migrator Pro's homepage is public — application-confluence-migrator-pro 7.5 High2025-03-07
CVE-2025-1714 Username Enumeration in Gliffy — Gliffy 7.1 -2025-03-05
CVE-2024-11153 Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More 5.3 Medium2025-03-05
CVE-2019-1815 Cisco Meraki MX67 and MX68 Sensitive Information Disclosure Vulnerability — Cisco Meraki MX Firmware 9.8 -2025-03-04
CVE-2024-58049 Huawei HarmonyOS 安全漏洞 — HarmonyOS 5.0 Medium2025-03-04
CVE-2024-58047 Huawei HarmonyOS 安全漏洞 — HarmonyOS 5.0 Medium2025-03-04
CVE-2025-1868 Information display on multiple products from Famatech Corp — Advanced IP Scanner 5.3 -2025-03-03

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.