Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-47923 Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — Mashov 5.3 Medium2024-12-30
CVE-2024-47922 Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — PRI WEB 7.5 High2024-12-30
CVE-2024-56509 changedetection.io has Improper Input Validation Leading to LFR/Path Traversal — changedetection.io 8.6 High2024-12-27
CVE-2024-12984 Amcrest IP2M-841B Web Interface webCapsConfig information disclosure — IP2M-841B 5.3 Medium2024-12-27
CVE-2020-9089 华为产品安全漏洞 — HUAWEI P30 Pro 3.3 Low2024-12-27
CVE-2020-9082 华为产品安全漏洞 — HUAWEI Mate 20 3.5 Low2024-12-27
CVE-2024-45805 OpenCTI leaks support information due to inadequate access control — opencti 4.3 Medium2024-12-26
CVE-2024-12896 Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosure — VIP S3020 G2 5.3 Medium2024-12-22
CVE-2023-31280 Exposure of Sensitive Information to an Unauthorized Actor — AirVantage, AirVantage-Capable Devices: All Sierra Wireless devices. 5.3 Medium2024-12-20
CVE-2024-11297 Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Page and Post Restriction 5.3 Medium2024-12-20
CVE-2024-54009 Hewlett Packard Enterprise Alletra Storage MP B10000 安全漏洞 — HPE Alletra Storage MP B10000 4.0 Medium2024-12-19
CVE-2024-52589 Moderators can view Screened emails even when the “moderators view emails” option is disabled in Discourse — discourse 2.2 Low2024-12-19
CVE-2024-53991 Potential Backup file leaked via Nginx in Discourse — discourse 7.5 High2024-12-19
CVE-2024-12560 Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication — Button Block – Design Stylish, Interactive, and Multi-Functional Buttons 4.3 Medium2024-12-19
CVE-2024-10548 WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Project Task List REST API — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker 6.5 Medium2024-12-19
CVE-2024-11291 Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.4 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction 5.3 Medium2024-12-18
CVE-2024-12340 Animation Addons for Elementor <= 1.1.6 - Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor Template — Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates 4.3 Medium2024-12-18
CVE-2024-11295 Simple Page Access Restriction <= 1.0.29 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Simple Page Access Restriction 5.3 Medium2024-12-18
CVE-2024-12250 Accept Authorize.NET Payments Using Contact Form 7 <= 2.2 - Unauthenticated Information Exposure — Accept Authorize.NET Payments Using Contact Form 7 5.3 Medium2024-12-18
CVE-2024-10356 ElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates — ElementsReady Addons for Elementor 4.3 Medium2024-12-17
CVE-2024-11280 PPWP – Password Protect Pages <= 1.9.5 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — PPWP – Password Protect Pages 5.3 Medium2024-12-17
CVE-2024-8326 s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information Exposure — s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions 8.8 High2024-12-17
CVE-2024-11294 Memberful <= 1.73.9 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Memberful – Membership Plugin 5.3 Medium2024-12-17
CVE-2021-26281 Information disclosure vulnerability in Alarm clock module — Alarm clock 5.5 Medium2024-12-17
CVE-2021-26279 Information disclosure vulnerability in Weather module — Weather 5.9 Medium2024-12-17
CVE-2024-35230 Welcome and About GeoServer pages communicate version and revision information — geoserver 5.3 Medium2024-12-16
CVE-2024-55951 Metabase sandboxed users could see filter values from other sandboxed users — metabase 5.0 -2024-12-16
CVE-2024-12578 Tickera – WordPress Event Ticketing <= 3.5.4.8 - Unauthenticated Customer Data Exposure — Tickera – Sell Tickets & Manage Events 5.3 Medium2024-12-14
CVE-2024-55946 Playloom Engine Data Storage Vulnerability — Playloom-Engine 6.5 -2024-12-13
CVE-2024-9945 Limited Information Disclosure in GoAnywhere MFT Prior to 7.7.0 — GoAnywhere MFT 5.3 Medium2024-12-13

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.