Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-7128 Openshift-console: unauthenticated data exposure 5.3 Medium2024-07-26
CVE-2024-5067 Exposure of Sensitive Information to an Unauthorized Actor in GitLab — GitLab 4.4 Medium2024-07-24
CVE-2024-7060 Exposure of Sensitive Information to an Unauthorized Actor in GitLab — GitLab 2.6 Low2024-07-24
CVE-2024-7091 Exposure of Sensitive Information to an Unauthorized Actor in GitLab — GitLab 4.1 Medium2024-07-24
CVE-2024-41672 DuckDB: sniff_csv provides filesystem access even when enable_external_access is disabled — duckdb 7.5 High2024-07-24
CVE-2024-39676 Apache Pinot: Unauthorized endpoint exposed sensitive information — Apache Pinot 5.3AIMediumAI2024-07-24
CVE-2024-6571 Optimize Images ALT Text (alt tag) & names for SEO using AI <= 3.1.1 - Unauthenticated Full Path Disclosure — Image SEO – AI-Driven Image SEO Optimizer 5.3 Medium2024-07-24
CVE-2024-6553 WP Meteor Website Speed Optimization Addon <= 3.4.3 - Unauthenticated Full Path Disclosure — WP Meteor Website Speed Optimization Addon 5.3 Medium2024-07-24
CVE-2024-23321 Apache RocketMQ: Unauthorized Exposure of Sensitive Data — Apache RocketMQ 8.8AIHighAI2024-07-22
CVE-2024-6560 Addonify – Quick View For WooCommerce <= 1.2.16 - Unauthenticated Full Path Dislcosure — Addonify – Quick View For WooCommerce 5.3 Medium2024-07-20
CVE-2024-6455 ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor 5.3 Medium2024-07-18
CVE-2024-40647 Unintentional exposure of environment variables to subprocesses in sentry-sdk — sentry-python 5.3 Medium2024-07-18
CVE-2024-29885 Reports are still accessible even when `canView()` returns false in silverstripe/reports — silverstripe-reports 4.3 Medium2024-07-17
CVE-2024-40633 Customer data leak via adjustments API endpoint in Sylius — Sylius 5.3 Medium2024-07-17
CVE-2024-20396 Cisco Webex 安全漏洞 — Cisco Webex Teams 5.3 Medium2024-07-17
CVE-2024-6395 GitHub Enterprise Server Information Disclosure Vulnerability Exposes Private Repository Names via Deploy Keys — GitHub Enterprise Server 5.3AIMediumAI2024-07-16
CVE-2024-6336 Security misconfiguration was identified in GitHub Enterprise Server that allowed sensitive data exposure — GitHub Enterprise Server 4.3AIMediumAI2024-07-16
CVE-2020-25836 Potential information leakage resulting in unauthorized access — NetIQ Directory and Resource Administrator 6.3 Medium2024-07-16
CVE-2022-45449 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect 15 7.5AIHighAI2024-07-16
CVE-2024-6565 AForms <= 2.2.6 - Unauthenticated Full Path Disclosure — AForms — Form Builder for Price Calculator & Cost Estimation 5.3 Medium2024-07-16
CVE-2024-6570 Glossary <= 2.2.26 - Unauthenticated Full Path Disclosure — Glossary 5.3 Medium2024-07-16
CVE-2024-6559 XCloner <= 4.7.3 - Unauthenticated Full Path Disclosure — Backup, Restore and Migrate your sites with XCloner 5.3 Medium2024-07-16
CVE-2024-6557 SchedulePress <= 5.1.3 - Unauthenticated Full Path Disclosure — SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher 5.3 Medium2024-07-16
CVE-2024-39919 Capture screenshot of localhost web services (unauthenticated pages) in @jmondi/url-to-png — url-to-png 3.1 Low2024-07-15
CVE-2024-6398 Trellix Secure Web Gateway 信息泄露漏洞 — Secure Web Gateway 4.3 Medium2024-07-15
CVE-2024-6574 Laposta <= 1.12 - Unauthenticated Full Path Disclosure — Laposta 5.3 Medium2024-07-13
CVE-2024-6555 WP Popups – WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure — WP Popups – WordPress Popup builder 5.3 Medium2024-07-12
CVE-2024-6407 Schneider Electric Wiser Home Controller WHC-5918A 信息泄露漏洞 — Wiser Home Controller WHC-5918A 9.8 Critical2024-07-11
CVE-2024-6554 Branda – White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure — Branda – White Label & Branding, Free Login Page Customizer 5.3 Medium2024-07-11
CVE-2024-6210 Duplicator <= 1.5.9 - Full Path Disclosure — Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More 5.3 Medium2024-07-11

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.