Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13829 WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure — WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto 5.3 Medium2025-02-05
CVE-2024-56197 Users can see other user's tagged PMs in Discourse — discourse 2.2 Low2025-02-04
CVE-2025-24373 Unrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slips — woocommerce-pdf-invoices-packing-slips 6.5 -2025-02-04
CVE-2025-24899 Disclosure of Sensitive User Information via API in reNgine — rengine 6.5 -2025-02-03
CVE-2025-23215 PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext — pmd 9.8 -2025-01-31
CVE-2024-11741 Grafana 安全漏洞 — Grafana 4.3 Medium2025-01-31
CVE-2024-13623 Order Export for WooCommerce <= 3.24 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Order Export for WooCommerce 5.9 Medium2025-01-31
CVE-2024-23937 Silicon Labs Gecko OS Debug Interface Format String — Gecko OS 4.3 Medium2025-01-31
CVE-2024-23962 Alpine Halo9 Missing Authentication — Halo9 5.3 Medium2025-01-30
CVE-2024-8494 Elementor Website Builder Pro – More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode — Elementor Website Builder Pro 4.3 Medium2025-01-30
CVE-2025-24884 kube-audit-rest's example logging configuration could disclose secret values in the audit log — kube-audit-rest 4.3 -2025-01-29
CVE-2025-23212 Tandoor Recipes - Local file disclosure - Users can read the content of any file on the server — recipes 7.7 High2025-01-28
CVE-2025-0659 Path Traversal and Rockwell Automation Third-party Vulnerability in DataMosaix™ Private Cloud — DataEdgePlatform DataMosaix™ Private Cloud 4.9 -2025-01-28
CVE-2024-11090 Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Membership Plugin – Restrict Content 5.3 Medium2025-01-26
CVE-2024-13562 Import WP – Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Import WP – Export and Import CSV and XML files to WordPress 7.5 High2025-01-25
CVE-2025-24360 Opening a malicious website while running a Nuxt dev server could allow read-only access to code — nuxt 5.3 Medium2025-01-25
CVE-2025-24363 The HL7 FHIR IG publisher may potentially expose GitHub repo user and credential information — fhir-ig-publisher 4.2 Medium2025-01-24
CVE-2025-22612 Coolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE) — coolify 10.0 Critical2025-01-24
CVE-2025-22607 Coolify Vulnerable to GitHub / GitLab OAuth Secrets Leak — coolify 6.5 -2025-01-24
CVE-2024-52975 Fleet Server sensitive information exposure via logs — Fleet Server 9.0 Critical2025-01-23
CVE-2024-43707 Kibana exposure of sensitive information to an unauthorized actor — Kibana 7.7 High2025-01-23
CVE-2025-23047 Cilium vulnerable to information leakage via insecure default Hubble UI CORS header — cilium 6.5 Medium2025-01-22
CVE-2025-24011 Umbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response Codes — Umbraco-CMS 5.3 Medium2025-01-21
CVE-2025-0318 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 5.3 Medium2025-01-18
CVE-2024-12142 Schneider Electric Modicon M340 信息泄露漏洞 — Modicon M340 processors (part numbers BMXP34*) 8.6 High2025-01-17
CVE-2024-12637 Moving Users <= 1.05 - Unauthenticated Sensitive Information Exposure — Moving Users 5.3 Medium2025-01-17
CVE-2024-56136 /api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip server — zulip 5.3 -2025-01-16
CVE-2025-0472 Information exposure vulnerability in PMB platform — PMB platform 7.5 High2025-01-16
CVE-2025-0481 D-Link DIR-878 HTTP POST Request dllog.cgi information disclosure — DIR-878 5.3 Medium2025-01-15
CVE-2025-23074 Special:EditProfile exposes the contents of profile fields marked "hidden"/friends or "friends of friends" when the privileged user isn't a friend of the user whose profile they edit(ed) — Mediawiki - SocialProfile Extension 9.1 -2025-01-14

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.