Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-29840 Broken Access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS in Evolution Controller allows unauthenticated attackers to retrieve PIN field values — Evolution Controller 7.5 High2024-04-14
CVE-2024-29839 Broken Access control on DESKTOP_EDIT_USER_GET_CARD in Evolution Controller allows unauthenticated attackers to retrieve card data values. — Evolution Controller 7.5 High2024-04-14
CVE-2024-29023 Session Hijacking via token exposure on the session page in Xibo CMS — xibo-cms 7.2 High2024-04-12
CVE-2024-30381 Paragon Active Assurance: probe_serviced exposes internal objects to local users — Paragon Active Assurance 8.4 High2024-04-12
CVE-2024-3689 Zhejiang Land Zongheng Network Technology O2OA information disclosure — O2OA 3.7 Low2024-04-12
CVE-2024-3706 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in OpenGnsys — OpenGnsys 5.9 Medium2024-04-12
CVE-2024-2966 Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.5.6 - Sensitive Information Exposure via element_pack_ajax_search — Element Pack – Widgets, Templates & Addons for Elementor 5.3 Medium2024-04-11
CVE-2024-31464 XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted — xwiki-platform 6.8 Medium2024-04-10
CVE-2024-1643 Unauthorized Organization Access in lunary-ai/lunary — lunary-ai/lunary 8.1AIHighAI2024-04-10
CVE-2024-31302 WordPress Contact Form Email plugin <= 1.3.44 - Sensitive Data Exposure vulnerability — Contact Form Email 5.3 Medium2024-04-10
CVE-2024-2093 VK All in One Expansion Unit <= 9.95.0.1 - Information Exposure — VK All in One Expansion Unit 6.5 Medium2024-04-09
CVE-2024-2974 Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure — Essential Addons for Elementor – Popular Elementor Templates & Widgets 5.3 Medium2024-04-09
CVE-2023-7046 WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score <= 7.0 - Sensitive Information Exposure via insufficiently protected files — WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan 7.5 High2024-04-09
CVE-2023-6777 WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service — WP Go Maps (formerly WP Google Maps) 5.3 Medium2024-04-09
CVE-2024-31455 Minder GetRepositoryByName data leak — minder 4.3 Medium2024-04-09
CVE-2024-28235 Contao possible cookie sharing with external domains while checking protected pages for broken links — contao 8.4 High2024-04-09
CVE-2024-23662 Fortinet FortiOS 信息泄露漏洞 — FortiOS 5.0 Medium2024-04-09
CVE-2024-30269 DataEase has database configuration information exposure vulnerability — dataease 5.3 Medium2024-04-08
CVE-2024-27897 Huawei HarmonyOS Wearables 安全漏洞 — HarmonyOS 7.5AIHighAI2024-04-08
CVE-2024-2950 BoldGrid Easy SEO – Simple and Effective SEO <= 1.6.14 - Information Exposure — BoldGrid Easy SEO – Simple and Effective SEO 5.3 Medium2024-04-06
CVE-2023-5692 WordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink — WordPress 5.3 Medium2024-04-05
CVE-2024-30263 The PDF Viewer macro can be used to view PDF attachments with restricted access — macro-pdfviewer 7.7 High2024-04-04
CVE-2024-31207 Vite's `server.fs.deny` did not deny requests for patterns with directories — vite 5.9 Medium2024-04-04
CVE-2024-3262 Information exposure vulnerability in Request Tracker (RT) — Request Tracker 5.5 Medium2024-04-04
CVE-2024-3274 D-Link DNS-320L/DNS-320LW/DNS-327L HTTP GET Request info.cgi information disclosure — DNS-320L 5.3 Medium2024-04-04
CVE-2023-38729 IBM Db2 information disclosure — Db2 for Linux, UNIX and Windows 6.8 Medium2024-04-03
CVE-2024-2931 WPFront User Role Editor <= 3.2.1.11184 - Limited Information Exposure — WPFront User Role Editor 4.3 Medium2024-04-02
CVE-2024-3160 Intelbras HDCVI 1016 HTTP GET Request cap.js information disclosure — MHDX 1004 5.3 Medium2024-04-02
CVE-2024-30469 WordPress Wholesale For WooCommerce plugin <= 2.3.0 - Unauthenticated Sensitive Data Exposure vulnerability — Wholesale For WooCommerce 5.3 Medium2024-03-29
CVE-2024-29898 Oversight in fix for GHSA-4rcf-3cj2-46mq may have exposed suppressed wiki requests on private wikis — CreateWiki 4.9 Medium2024-03-28

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.