Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-5160 Full name disclosure via team top membership with Show Full Name option disabled — Mattermost 4.3 Medium2023-10-02
CVE-2023-5256 Drupal core - Critical - Cache poisoning - SA-CORE-2023-006 — Core 9.1 -2023-09-28
CVE-2023-40049 WS_FTP Server Information Disclosure via Directory Listing — WS_FTP Server 5.3 Medium2023-09-27
CVE-2023-41323 Users login enumeration by unauthenticated user in GLPI — glpi 5.3 Medium2023-09-26
CVE-2023-23958 Symantec Protection Engine Hash Leak Vulnerability — Symantec Protection Engine 6.8 Medium2023-09-26
CVE-2023-41321 Sensitive fields enumeration through API in GLPI — glpi 4.9 Medium2023-09-26
CVE-2023-42820 Random seed leakage in Jumpserver — jumpserver 7.0 High2023-09-26
CVE-2023-5166 Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL — Docker Desktop 8.0 High2023-09-25
CVE-2023-1633 Insecure barbican configuration file leaking credential — openstack-barbican 6.6 Medium2023-09-24
CVE-2023-5134 Easy Registration Forms <= 2.1.1 - Authenticated (Subscriber+) Information Disclosure via Shortcode — Easy Registration Forms 4.3 Medium2023-09-23
CVE-2023-38718 IBM Robotic Process Automation information disclosure — Robotic Process Automation 3.7 Low2023-09-20
CVE-2023-40368 IBM Storage Protect information disclosure — Storage Protect Client 4.4 Medium2023-09-20
CVE-2022-47554 Exposure of Sensitive Information in Ormazabal products — ekorCCP 8.2 High2023-09-19
CVE-2023-42454 SQLpage vulnerable to public exposure of database credentials — SQLpage 10.0 Critical2023-09-18
CVE-2023-37263 Strapi's field level permissions not being respected in relationship title — strapi 6.8 Medium2023-09-15
CVE-2023-36472 Strapi may leak sensitive user information, user reset password, tokens via content-manager views — strapi 5.8 Medium2023-09-15
CVE-2021-44172 Fortinet FortiClientEms 信息泄露漏洞 — FortiClientEMS 3.6 Medium2023-09-13
CVE-2023-36551 Fortinet FortiSIEM 安全漏洞 — FortiSIEM 4.2 Medium2023-09-13
CVE-2023-4917 Leyka <= 3.30.7 - Authenticated (Subscriber+) Sensitive Information Exposure — Leyka 5.3 Medium2023-09-13
CVE-2023-36763 Microsoft Outlook Information Disclosure Vulnerability — Microsoft Office 2019 7.5 High2023-09-12
CVE-2023-40712 Apache Airflow: Secrets can be unmasked in the "Rendered Template" — Apache Airflow 4.3 -2023-09-12
CVE-2023-4877 Exposure of Sensitive Information to an Unauthorized Actor in hamza417/inure — hamza417/inure 7.5 -2023-09-10
CVE-2023-4876 Exposure of Sensitive Information to an Unauthorized Actor in hamza417/inure — hamza417/inure 7.5 -2023-09-10
CVE-2022-22409 IBM Aspera Faspex information disclosure — Aspera Faspex 5.3 Medium2023-09-08
CVE-2023-40029 Cluster secret might leak in cluster details page in Argo CD — argo-cd 9.9 Critical2023-09-07
CVE-2023-41050 Information disclosure through Python's "format" functionality in Zope AccessControl — AccessControl 6.8 Medium2023-09-06
CVE-2023-32271 Open Automation Software OAS Platform 信息泄露漏洞 — OAS Platform 6.5 Medium2023-09-05
CVE-2023-4714 PlayTube Redirect information disclosure — PlayTube 4.3 Medium2023-09-01
CVE-2023-23763 Information disclosure in GitHub Enterprise Server leading to private repository leakage — Enterprise Server 5.3 Medium2023-09-01
CVE-2022-4343 Exposure of Sensitive Information to an Unauthorized Actor in GitLab — GitLab 5.0 Medium2023-09-01

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.