Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-25130 Tuleap's mass update clears the permissions on artifact field — tuleap 5.4 Medium2024-02-22
CVE-2024-24817 User can see invitees in events created in PMs and private categories — discourse-calendar 4.3 Medium2024-02-22
CVE-2024-26136 kedi ElectronCord's Discord Token is public — ElectronCord 7.5 High2024-02-20
CVE-2024-0620 PPWP – Password Protect Pages <= 1.8.9 - Protection Mechanism Bypass — PPWP – Password Protect Pages 5.3 Medium2024-02-20
CVE-2024-0616 Passster – Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposure — Passster – Password Protect Pages and Content 5.3 Medium2024-02-20
CVE-2024-26132 Element Android can be asked to share internal files. — element-android 4.0 Medium2024-02-20
CVE-2023-52097 Huawei EMUI 安全漏洞 — HarmonyOS 6.5AIMediumAI2024-02-18
CVE-2024-24758 Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undici — undici 3.9 Low2024-02-16
CVE-2024-1591 Privilege Management for Windows < 24.1 Information Leak — Privilege Management for Windows 3.3 Low2024-02-16
CVE-2023-44253 Fortinet FortiManager 信息泄露漏洞 — FortiManager 4.7 Medium2024-02-15
CVE-2024-0708 Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.2 - Unauthenticated Information Exposure — Landing Page Cat – Coming Soon & Maintenance Pages 5.3 Medium2024-02-15
CVE-2024-25118 Information Disclosure of Hashed Passwords in TYPO3 Backend Forms — typo3 4.3 Medium2024-02-13
CVE-2024-25119 Information Disclosure of Encryption Key in TYPO3 Install Tool — typo3 4.9 Medium2024-02-13
CVE-2024-25120 Improper Access Control of Resources Referenced by t3:// URI Scheme in TYPO3 — typo3 4.3 Medium2024-02-13
CVE-2024-25121 Improper Access Control Persisting File Abstraction Layer Entities via Data Handler in TYPO3 — typo3 7.1 High2024-02-13
CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability — Microsoft Dynamics 365 Business Central 2022 Release Wave 2 8.0 High2024-02-13
CVE-2022-22506 IBM Robotic Process Automation information disclosure — Robotic Process Automation 4.6 Medium2024-02-12
CVE-2024-1431 Netgear R7000 Web Management Interface debuginfo.htm information disclosure — R7000 4.3 Medium2024-02-11
CVE-2024-1430 Netgear R7000 Web Management Interface currentsetting.htm information disclosure — R7000 4.3 Medium2024-02-11
CVE-2024-1406 Linksys WRT54GL Web Management Interface SysInfo1.htm information disclosure — WRT54GL 4.3 Medium2024-02-10
CVE-2024-1405 Linksys WRT54GL Web Management Interface wlaninfo.htm information disclosure — WRT54GL 4.3 Medium2024-02-10
CVE-2024-1404 Linksys WRT54GL Web Management Interface SysInfo.htm information disclosure — WRT54GL 4.3 Medium2024-02-09
CVE-2024-21624 Potential Information Leak in User-Constructed Message Templates in nonebot2 — nonebot2 5.7 Medium2024-02-09
CVE-2023-50298 Apache Solr: Solr can expose ZooKeeper credentials via Streaming Expressions — Apache Solr 7.5 -2024-02-09
CVE-2024-24825 TokenManager not checking permissions on cached tokens in DIRAC — DIRAC 9.1 Critical2024-02-08
CVE-2024-0242 Unauthorized access to settings in Qolsys IQ Panel 4 and IQ4 Hub — IQ Panel 4 7.3 High2024-02-08
CVE-2024-1255 sepidz SepidzDigitalMenu Waiters information disclosure — SepidzDigitalMenu 5.3 Medium2024-02-06
CVE-2024-22331 IBM UrbanCode Deploy information disclosure — UrbanCode Deploy 6.2 Medium2024-02-06
CVE-2023-46183 IBM PowerVM Hypervisor information disclosure — PowerVM Hypervisor 5.3 Medium2024-02-06
CVE-2024-23344 Tuleap's content of artifacts might be readable by unauthorized users — tuleap 5.3 Medium2024-02-06

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.