Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-23073 API list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameter — Mediawiki - GlobalBlocking Extension 7.5 -2025-01-14
CVE-2024-50338 Carriage-return character in remote URL allows malicious repository to leak credentials in Git Credential Manager — git-credential-manager 7.4 High2025-01-14
CVE-2025-21308 Windows Themes Spoofing Vulnerability — Windows 10 Version 1507 6.5 Medium2025-01-14
CVE-2025-21242 Windows Kerberos Information Disclosure Vulnerability — Windows 10 Version 1507 5.9 Medium2025-01-14
CVE-2025-21214 Windows BitLocker Information Disclosure Vulnerability — Windows 10 Version 1507 4.2 Medium2025-01-14
CVE-2024-12008 W3 Total Cache <= 2.8.1 Information Exposure via Log Files — W3 Total Cache 5.3 Medium2025-01-14
CVE-2025-22138 Private categories allow suggested edits to be viewed via the queue in @codidact/qpixel — qpixel 4.3 -2025-01-13
CVE-2025-22828 Apache CloudStack: Unauthorised access to annotations — Apache CloudStack 4.2 -2025-01-13
CVE-2025-0403 1902756969 reggie Phone Number Validation sendMsg information disclosure — reggie 5.3 Medium2025-01-13
CVE-2024-42179 HCL MyXalytics is affected by sensitive information disclosure vulnerability — DRYiCE MyXalytics 2.0 Low2025-01-12
CVE-2025-21592 Junos OS: SRX Series: Low privileged user able to access highly sensitive information on file system — Junos OS 5.5 Medium2025-01-09
CVE-2023-24012 Data Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Open DDS — DDS 8.2 High2025-01-09
CVE-2023-24011 Data Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Cyclone DDS — DDS 8.2 High2025-01-09
CVE-2023-24010 Data Distribution Service (DDS) Chain of Trust (CoT) violation in Fast DDS — DDS 8.2 High2025-01-09
CVE-2024-12584 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post Duplication — Xpro Addons — 140+ Widgets for Elementor 4.3 Medium2025-01-08
CVE-2024-56443 Huawei HarmonyOS 信息泄露漏洞 — HarmonyOS 6.2 Medium2025-01-08
CVE-2024-12426 URL fetching can be used to exfiltrate arbitrary INI file values and environment variables — LibreOffice 6.5 -2025-01-07
CVE-2024-12532 BWD Elementor Addons <= 4.3.18 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates — BWD Elementor Addons 4.3 Medium2025-01-07
CVE-2024-11282 Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Passster – Password Protect Pages and Content 5.3 Medium2025-01-07
CVE-2024-12159 Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposure — Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords 5.3 Medium2025-01-07
CVE-2024-12140 Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Contributor+) Private Templates Content Disclosure — Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements 4.3 Medium2025-01-07
CVE-2024-11290 Member Access <= 1.1.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Member Access 5.3 Medium2025-01-07
CVE-2024-12538 Duplicate Post, Page and Any Custom Post <= 3.5.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication — Duplicate Post, Page and Any Custom Post 4.3 Medium2025-01-07
CVE-2025-21620 Deno's authorization headers not dropped when redirecting cross-origin — deno 7.5 High2025-01-06
CVE-2025-21615 AAT allows data exfiltration by other apps installed on the same device — AAT 5.5 Medium2025-01-06
CVE-2025-0227 Tsinghua Unigroup Electronic Archives System downLoad.html information disclosure — Electronic Archives System 4.3 Medium2025-01-05
CVE-2025-0226 Tsinghua Unigroup Electronic Archives System downLoad.html download information disclosure — Electronic Archives System 4.3 Medium2025-01-05
CVE-2025-0224 Provision-ISR SH-4050A-2 server.js information disclosure — SH-4050A-2 5.3 Medium2025-01-05
CVE-2024-13110 Beijing Yunfan Internet Technology Yunfan Learning Examination System Exam Answer PaperController.java, information disclosure — Yunfan Learning Examination System 4.3 Medium2025-01-02
CVE-2024-13042 Tsinghua Unigroup Electronic Archives Management System download.html download information disclosure — Electronic Archives Management System 4.3 Medium2024-12-30

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.