Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8461 D-Link DNS-320 Web Management Interface discovery.cgi information disclosure — DNS-320 5.3 Medium2024-09-05
CVE-2024-8460 D-Link DNS-320 Web Management Interface widget_api.cgi information disclosure — DNS-320 3.7 Low2024-09-05
CVE-2024-6835 Ivory Search – WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form — Ivory Search – WordPress Search Plugin 5.3 Medium2024-09-05
CVE-2024-20503 Cisco Duo Epic for Hyperdrive Information Disclosure Vulnerability — Cisco Duo Authentication for Epic 5.5 Medium2024-09-04
CVE-2024-8106 The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure — The Ultimate WordPress Toolkit – WP Extended 6.5 Medium2024-09-04
CVE-2024-45447 Huawei HarmonyOS 安全漏洞 — HarmonyOS 4.4 Medium2024-09-04
CVE-2024-45450 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 4.0 Medium2024-09-04
CVE-2024-45391 Tina search token leak via lock file in TinaCMS — tinacms 7.5 High2024-09-03
CVE-2024-43803 BMO can expose particularly named secrets from other namespaces via BMH CRD — baremetal-operator 4.9 Medium2024-09-03
CVE-2024-43801 Privilege escalation to admin from a low-privileged user via SVG upload in Jellyfin — jellyfin 4.6 Medium2024-09-02
CVE-2024-45388 Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`) — hoverfly 7.5 High2024-09-02
CVE-2024-3679 Premium SEO Pack – WP SEO Plugin <= 1.6.002 - Unauthenticated Information Exposure — Premium SEO Pack – WP SEO Plugin 5.3 Medium2024-08-29
CVE-2024-2541 Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File — Popup Builder – Create highly converting, mobile friendly marketing popups. 5.3 Medium2024-08-29
CVE-2024-6551 GiveWP <= 3.15.1 - Unauthenticated Full Path Disclosure — GiveWP – Donation Plugin and Fundraising Platform 5.3 Medium2024-08-29
CVE-2024-7418 The Post Grid <= 7.7.11 - Authenticated (Contributor+) Information Disclosure — The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid 4.3 Medium2024-08-29
CVE-2024-45043 OpenTelemetry Collector AWS Firehose Receiver Authentication Bypass Vulnerability — opentelemetry-collector-contrib 5.3 Medium2024-08-28
CVE-2024-45054 Potential Permission Leakage of Cluster Level in hwameistor — hwameistor 2.8 Low2024-08-28
CVE-2021-22529 Sensitive Data Exposure leaks potential information in NetIQ Advance Authentication — NetIQ Advance Authentication 6.3 Medium2024-08-28
CVE-2024-6448 Mollie Payments for WooCommerce <= 7.7.0 - Unauthenticated Full Path Disclosure — Mollie Payments for WooCommerce 5.3 Medium2024-08-28
CVE-2024-6633 Insecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier) — FileCatalyst Workflow 9.8 Critical2024-08-27
CVE-2024-43251 WordPress Bit Form Pro plugin <= 2.6.4 - Authenticated Sensitive Data Exposure vulnerability — Bit Form Pro 6.5 Medium2024-08-26
CVE-2024-43257 WordPress Leopard plugin <= 2.0.36 - Subscriber+ Sensitive Data Exposure vulnerability — Leopard - WordPress offload media 6.5 Medium2024-08-26
CVE-2024-43258 WordPress Store Locator Plus® for WordPress plugin <= 2311.17.01 - Sensitive Data Exposure vulnerability — Store Locator Plus 5.3 Medium2024-08-26
CVE-2024-43289 WordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerability — wpForo Forum 7.5 High2024-08-26
CVE-2024-43319 WordPress HTML5 Video Player plugin <= 2.5.31 - Sensitive Data Exposure vulnerability — Flash & HTML5 Video 4.3 Medium2024-08-26
CVE-2024-42339 CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — CyberArk Identity Management 4.3 Medium2024-08-25
CVE-2024-42338 CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — CyberArk Identity Management 4.3 Medium2024-08-25
CVE-2024-42337 CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — CyberArk Identity Management 4.3 Medium2024-08-25
CVE-2024-6499 WordPress Button Plugin MaxButtons <= 9.7.8 - Full Path Disclosure — MaxButtons – Create buttons 5.3 Medium2024-08-24
CVE-2024-8072 Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users 5.3 Medium2024-08-22

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.