Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-22032 Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpec — rancher 6.5 Medium2024-10-16
CVE-2017-20194 Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder 5.3 Medium2024-10-16
CVE-2024-9540 Sina Extension for Elementor <= 3.5.7 - Authenticated (Contributor+) Sensitive Information Exposure via Sina Modal Box Widget Elementor Template — Sina Extension for Elementor 4.3 Medium2024-10-16
CVE-2020-36835 Migration, Backup, Staging – WPvivid <= 0.9.35 - Sensitive Information Disclosure — WPvivid — Backup, Migration & Staging 4.9 Medium2024-10-16
CVE-2024-47824 Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room — matrix-react-sdk 6.5 -2024-10-15
CVE-2024-47779 Element Web vulnerable to potential exposure of access token via authenticated media — element-web 7.5 -2024-10-15
CVE-2024-47771 Element Desktop vulnerable to potential exposure of access token via authenticated media — element-desktop 7.5 -2024-10-15
CVE-2024-47080 matrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeserver — matrix-js-sdk 7.5 -2024-10-15
CVE-2024-6757 Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function — Elementor Website Builder – more than just a page builder 4.3 Medium2024-10-15
CVE-2024-9546 WPIDE <= 3.4.9 - Unauthenticated Full Path Dislcosure — WPIDE – File Manager & Code Editor 5.3 Medium2024-10-14
CVE-2024-45739 Sensitive information disclosure in AdminManager logging channel — Splunk Enterprise 4.9 Medium2024-10-14
CVE-2024-45738 Sensitive information disclosure in REST_Calls logging channel — Splunk Enterprise 4.9 Medium2024-10-14
CVE-2024-8902 Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections — Addon Elements for Elementor (formerly Elementor Addon Elements) 4.3 Medium2024-10-12
CVE-2024-9821 Bot for Telegram on WooCommerce <= 1.2.7 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass — Bot for Telegram on WooCommerce 8.8 High2024-10-12
CVE-2024-9539 GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server 4.3AIMediumAI2024-10-11
CVE-2024-39527 Junos OS: SRX Series: Low privileged user able to access sensitive information on file system — Junos OS 5.5 Medium2024-10-11
CVE-2024-9538 ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin 4.3 Medium2024-10-11
CVE-2024-8913 The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce 4.3 Medium2024-10-11
CVE-2024-47868 Several components’ post-process steps may allow arbitrary file leaks in Gradio — gradio 7.5AIHighAI2024-10-10
CVE-2024-45134 Adobe Commerce | Information Exposure (CWE-200) — Adobe Commerce 2.7 Low2024-10-10
CVE-2024-30118 HCL Connections is susceptible to a sensitive information disclosure vulnerability — Connections 3.5 Low2024-10-09
CVE-2024-3656 Keycloak: unguarded admin rest api endpoints allows low privilege users to use administrative functionalities 8.1 High2024-10-09
CVE-2024-43610 Copilot Studio Information Disclosure Vulnerability — Microsoft Copilot Studio 7.4 High2024-10-09
CVE-2024-43609 Microsoft Office Spoofing Vulnerability — Microsoft Office LTSC 2024 6.5 Medium2024-10-08
CVE-2024-33506 Fortinet FortiManager 信息泄露漏洞 — FortiManager 3.1 Low2024-10-08
CVE-2024-8884 Schneider Electric System Monitor application 信息泄露漏洞 — System Monitor application in Harmony Industrial PC HMIBMO/HMIBMI/HMIPSO/HMIBMP/HMIBMU/HMIPSP/HMIPEP series 9.8 Critical2024-10-08
CVE-2024-47344 WordPress uListing plugin <= 2.1.5 - Sensitive Data Exposure vulnerability — uListing 5.3 Medium2024-10-07
CVE-2024-45250 ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor — iClock v3.1-168 4.3 Medium2024-10-06
CVE-2024-45245 Diebold Nixdorf – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — Vynamic View prior 7.8 High2024-10-06
CVE-2024-47848 User can review/unreview articles while blocked — Mediawiki - PageTriage 9.8 -2024-10-04

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.