Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-38859 IBM Security Verify Privilege information disclosure — Security Verify Privilege 4.3 Medium2023-10-17
CVE-2012-10016 Halulu simple-download-button-shortcode Plugin Download simple-download-button_dl.php information disclosure — simple-download-button-shortcode Plugin 4.3 Medium2023-10-16
CVE-2023-45131 Unauthenticated access to new private chat messages in Discourse — discourse 7.5 High2023-10-16
CVE-2023-44391 Prevent unauthorized access to summary details in Discourse — discourse 5.3 Medium2023-10-16
CVE-2023-43814 Exposure of poll options and votes to unauthorized users in Discourse — discourse 3.7 Low2023-10-16
CVE-2023-44394 Disclosure of project names to unauthorized users in MantisBT — mantisbt 4.3 Medium2023-10-16
CVE-2023-45147 Arbitrary keys can be added to a topic's custom fields by any user in Discourse — discourse 4.9 Medium2023-10-16
CVE-2023-38059 External pictures can be loaded even if not allowed by configuration — OTRS 5.3 Medium2023-10-16
CVE-2022-43868 IBM Security Verify Access information disclosure — Security Verify Access 5.3 Medium2023-10-14
CVE-2023-5579 yhz66 Sandbox User Data information disclosure — Sandbox 3.5 Low2023-10-14
CVE-2023-42663 Apache Airflow: Bypass permission verification to view task instances of other dags — Apache Airflow 4.3 -2023-10-14
CVE-2023-45348 Apache Airflow: Configuration information leakage vulnerability — Apache Airflow 4.3 -2023-10-14
CVE-2023-42780 Apache Airflow: Improper access control vulnerability in the "List dag warnings" feature — Apache Airflow 4.3 -2023-10-14
CVE-2023-39999 WordPress < 6.3.2 is vulnerable to Broken Access Control — WordPress 4.3 Medium2023-10-13
CVE-2023-45143 Undici's cookie header not cleared on cross-origin redirect in fetch — undici 3.9 Low2023-10-12
CVE-2023-44187 Junos OS Evolved: 'file copy' CLI command can disclose password to shell users — Junos OS Evolved 5.9 Medium2023-10-11
CVE-2023-41881 Deleting a collaboration should also delete linked resources — vantage6 3.7 Low2023-10-11
CVE-2023-44097 Huawei HarmonyOS 信息泄露漏洞 — HarmonyOS 6.5 -2023-10-11
CVE-2023-29348 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability — Windows Server 2019 7.5 High2023-10-10
CVE-2023-37939 Fortinet FortiClient 安全漏洞 — FortiClientMac 3.0 Low2023-10-10
CVE-2023-30804 Sangfor Next-Gen Application Firewall Authenticated File Disclosure — Net-Gen Application Firewall 4.9 Medium2023-10-10
CVE-2023-45219 BIG-IP tmsh vulnerability — BIG-IP 4.4 Medium2023-10-10
CVE-2022-34355 IBM Jazz Foundation information disclosure — Engineering Lifecycle Management 4.0 Medium2023-10-06
CVE-2023-43804 `Cookie` HTTP header isn't stripped on cross-origin redirects — urllib3 5.9 Medium2023-10-04
CVE-2023-3361 S3 credentials included when exporting elyra notebook — odh-dashboard 7.7 High2023-10-04
CVE-2023-1584 Quarkus-oidc: id and access tokens leak via the authorization code flow 7.5 High2023-10-04
CVE-2022-22447 IBM Disconnected Log Collector information disclosure — Disconnected Log Collector 4.0 Medium2023-10-03
CVE-2023-4886 Foreman: world readable file containing secrets — Red Hat Satellite 6.13 for RHEL 8 6.7 Medium2023-10-03
CVE-2023-3349 Information exposure on IBERMATICA RPS — IBERMATICA RPS 2019 8.2 High2023-10-03
CVE-2022-47892 Information disclosure in NetMan 204 — Netman-204 5.3 Medium2023-10-03

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.