Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-5968 Password hash in response body after username update — Mattermost 4.9 Medium2023-11-06
CVE-2021-4430 Ortus Solutions ColdBox Elixir ENV Variable defaultConfig.js information disclosure — ColdBox Elixir 3.5 Low2023-11-06
CVE-2023-45189 IBM Robotic Process Automation information disclosure — Robotic Process Automation 6.5 Medium2023-11-03
CVE-2023-41354 Chunghwa Telecom NOKIA G-040W-Q - Exposure of Sensitive Information — NOKIA G-040W-Q 4.0 Medium2023-11-03
CVE-2023-5920 Lack Of Secure Keyboard Entry Protection in MacOS Desktop — Mattermost Desktop 2.9 Low2023-11-02
CVE-2023-5516 Hitachi Energy Electronic Shift Operations Management System 安全漏洞 — eSOMS 5.3 Medium2023-11-01
CVE-2023-5515 Hitachi eSOMS 信息泄露漏洞 — eSOMS 5.3 Medium2023-11-01
CVE-2023-43796 Synapse vulnerable to leak of remote user device information — synapse 5.3 Medium2023-10-31
CVE-2023-43041 IBM QRadar information disclosure — QRadar SIEM 6.5 Medium2023-10-29
CVE-2022-3611 Lenovo App Store 信息泄露漏洞 — App Store 7.6 High2023-10-27
CVE-2023-31416 Elastic Cloud on Kubernetes (ECK) secret token configuration issue — Elastic Cloud on Kubernetes 5.3 Medium2023-10-26
CVE-2023-42490 EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor — v3.0.6433.1964 7.5 High2023-10-25
CVE-2023-46125 Fides Information Disclosure Vulnerability in Config API Endpoint — fides 6.5 Medium2023-10-24
CVE-2023-46128 Exposure of hashed user passwords via REST API in Nautobot — nautobot 6.5 Medium2023-10-24
CVE-2023-46288 Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set — Apache Airflow 4.3 -2023-10-23
CVE-2023-5718 Vue.js vue-devtools 访问控制错误漏洞 — Vue.js devtools 4.3 Medium2023-10-23
CVE-2023-5070 Social Media Share Buttons & Social Sharing Icons <= 2.8.5 - Information Exposure — Social Media Share Buttons & Social Sharing Icons 6.5 Medium2023-10-20
CVE-2023-4796 Booster for WooCommerce <= 7.1.0 - Authenticated (Subscriber+) Information Disclosure via Shortcode — Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools 4.3 Medium2023-10-20
CVE-2023-5576 Migration, Backup, Staging – WPvivid <= 0.9.91 - Google Drive Client Secret Exposure — WPvivid — Backup, Migration & Staging 8.0 High2023-10-20
CVE-2023-46115 Updater Private Keys Possibly Leaked via Vite Environment Variables in tauri-cli — tauri 8.4 High2023-10-19
CVE-2023-41893 Account takeover via auth_callback login in Home Assistant Core — core 4.3 Medium2023-10-19
CVE-2023-45809 Disclosure of user names via admin bulk action views in wagtail — wagtail 2.7 Low2023-10-19
CVE-2023-42666 Exposure of Sensitive Information to an Unauthorized Actor in DEXMA DEXGate — DexGate 5.3 Medium2023-10-19
CVE-2023-5254 AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 5.3 Medium2023-10-19
CVE-2023-5642 Advantech R-SeeNet Unauthenticated Read/Write — R-SeeNet 9.8 Critical2023-10-18
CVE-2023-5552 Sophos Firewall 信息泄露漏洞 — Sophos Firewall 7.1 High2023-10-17
CVE-2023-45803 Request body not stripped after redirect in urllib3 — urllib3 4.2 Medium2023-10-17
CVE-2023-5339 Mattermost Desktop logs all keystrokes during initial run after fresh installation  — Mattermost 4.7 Medium2023-10-17
CVE-2023-41752 Apache Traffic Server: s3_auth plugin problem with hash calculation — Apache Traffic Server 7.5 -2023-10-17
CVE-2022-43889 IBM Security Verify Privilege information disclosure — Security Verify Privilege 5.3 Medium2023-10-17

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.