Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-23523 WordPress Elementor Pro plugin <= 3.19.2 - Contributor+ Arbitrary User Meta Data Retrieval vulnerability — Elementor Pro 6.5 Medium2024-03-16
CVE-2024-28242 Disclosure of the existence of secret categories with custom backgrounds in Discourse — discourse 5.3 Medium2024-03-15
CVE-2024-24748 Disclosure of the existence of secret subcategories in Discourse — discourse 5.3 Medium2024-03-15
CVE-2024-28849 Proxy-Authorization header kept across hosts in follow-redirects — follow-redirects 6.5 Medium2024-03-14
CVE-2024-28193 Disclosure of Spotify API Access Tokens to Guest Users Using Public Tokens in your_spotify — your_spotify 6.5 Medium2024-03-13
CVE-2024-1083 Simple Restrict <= 1.2.6 - Missing Authorization to Sensitive Information Exposure — Simple Restrict 5.3 Medium2024-03-13
CVE-2024-2106 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route — MasterStudy LMS WordPress Plugin – for Online Courses and Education 5.3 Medium2024-03-13
CVE-2024-1979 Quarkus: information leak in annotation 3.5 Low2024-03-13
CVE-2024-28238 Session Token in URL in directus — directus 2.3 Low2024-03-12
CVE-2024-26177 Windows Kernel Information Disclosure Vulnerability — Windows 10 Version 1809 5.5 Medium2024-03-12
CVE-2024-1302 Multiple Vulnerabilities in Badger Meter's Monitool — Monitool 7.3 High2024-03-12
CVE-2024-2371 Information exposure vulnerability in Korenix JetI/O 6550 — JetI/O 6550 6.2 Medium2024-03-12
CVE-2024-0906 f(x) Private Site <= 1.2.1 - Sensitive Information Exposure — f(x) Private Site 5.3 Medium2024-03-12
CVE-2024-25114 Sensitive Information Disclosure (JailID) to users in Collabora Online — online 2.6 Low2024-03-11
CVE-2024-1460 MSI Afterburner v4.6.5.16370 - Kernel Memory Leak — MSI Afterburner 5.6 Medium2024-03-07
CVE-2024-24765 CasaOS-UserService allows unauthorized access to any file — CasaOS-UserService 7.5 High2024-03-06
CVE-2024-20292 Cisco Duo 安全漏洞 — Cisco Duo 4.4 Medium2024-03-06
CVE-2024-1769 JM Twitter Cards <= 14 - Information Exposure via Meta Description — JM Twitter Cards 5.3 Medium2024-03-05
CVE-2022-43890 IBM Security Verify Privilege On-Premises information disclosure — Security Verify Privilege On-Premises 5.3 Medium2024-03-04
CVE-2024-0765 Default user role exporting save state of instance — mintplex-labs/anything-llm 6.5 -2024-03-03
CVE-2024-27296 Directus version number disclosure — directus 5.3 Medium2024-03-01
CVE-2023-50324 IBM Cognos Command Center information disclosure — Cognos Command Center 5.3 Medium2024-03-01
CVE-2024-1952 Mattermost 安全漏洞 — Mattermost 3.1 Low2024-02-29
CVE-2024-1949 Mattermost 安全漏洞 — Mattermost 2.6 Low2024-02-29
CVE-2024-23493 Team associated AD/LDAP Groups Leaked due to missing authorization — Mattermost 4.3 Medium2024-02-29
CVE-2023-6922 Under Construction / Maintenance Mode from Acurax <= 2.6 - Authenticated (Subscriber+) Sensitive Information Exposure — Under Construction / Maintenance Mode from Acurax 4.3 Medium2024-02-28
CVE-2024-26144 Possible Sensitive Session Information Leak in Active Storage — rails 5.3 Medium2024-02-27
CVE-2024-27905 Apache Aurora: padding oracle can allow construction an authentication cookie — Apache Aurora 9.8 -2024-02-27
CVE-2024-1436 WordPress WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin <= 1.0.9 is vulnerable to Sensitive Data Exposure — WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit 5.3 Medium2024-02-26
CVE-2024-21501 Apostrophe sanitize-html 安全漏洞 — sanitize-html 5.3 Medium2024-02-24

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.