Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-32082 etcd key name can be accessed via LeaseTimeToLive API — etcd 3.1 Low2023-05-11
CVE-2023-28357 Rocket.Chat 信息泄露漏洞 — Rocket.Chat 4.3 -2023-05-11
CVE-2023-29106 Siemens SIMATIC Cloud Connect 信息泄露漏洞 — SIMATIC Cloud Connect 7 CC712 5.3 Medium2023-05-09
CVE-2023-32113 Information Disclosure vulnerability in SAP GUI for Windows — SAP GUI for Windows 7.5 High2023-05-09
CVE-2023-31404 Information Disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Service) — SAP BusinessObjects Business Intelligence Platform (Central Management Service) 5.0 Medium2023-05-09
CVE-2023-30740 Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform — SAP BusinessObjects Business Intelligence Platform 6.3 Medium2023-05-09
CVE-2023-28762 Information Disclosure in SAP BusinessObjects Intelligence Platform — SAP BusinessObjects Intelligence Platform 9.1 Critical2023-05-09
CVE-2023-22813 Device API endpoint missing access controls on Western Digital Mobile and Web Apps — My Cloud OS 5 Mobile App 3.3 Low2023-05-08
CVE-2023-31133 Ghost vulnerable to disclosure of private API fields — Ghost 7.5 High2023-05-08
CVE-2023-24505 Milesight NCR/Camera CWE-200: Exposure of Sensitive Information — NCR/Camera 5.3 Medium2023-05-08
CVE-2023-31413 Elastic Filebeat 日志信息泄露漏洞 — Filebeat 7.5 -2023-05-04
CVE-2023-26268 Apache CouchDB, IBM Cloudant: Information sharing via couchjs processes — Apache CouchDB 4.4 Medium2023-05-02
CVE-2023-30853 Gradle Build Action data written to GitHub Actions Cache may expose secrets — gradle-build-action 7.6 High2023-04-28
CVE-2023-28770 Zyxel DX5401-B0 安全漏洞 — DX5401-B0 firmware 7.5 High2023-04-27
CVE-2023-30843 Payload's hidden fields can be leaked on readable collections — payload 7.4 High2023-04-26
CVE-2023-30841 Ironic and ironic-inspector deployed within Baremetal Operator may expose as ConfigMaps — baremetal-operator 6.0 Medium2023-04-26
CVE-2023-1387 Grafana 安全漏洞 — Grafana 4.2 Medium2023-04-26
CVE-2023-2281 Archiving a team broadcasts unsanitized data over WebSockets — Mattermost 3.1 Low2023-04-25
CVE-2023-23839 SolarWinds Platform Exposure of Sensitive Information Vulnerability — SolarWinds Platform 6.5 Medium2023-04-25
CVE-2023-22577 White Rabbit Switch - Password Disclosure Vulnerability — White Rabbit Switch 9.8 Critical2023-04-24
CVE-2023-30611 Reaction metadata exposed in private topics in Discourse-reactions — discourse-reactions 4.3 Medium2023-04-19
CVE-2023-29517 Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewer — xwiki-platform 7.5 High2023-04-18
CVE-2023-26049 Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty — jetty.project 2.4 Low2023-04-18
CVE-2023-22307 Site-Passwords in GET parameters — Checkmk Appliance 5.5 Medium2023-04-18
CVE-2023-30540 Chat poll data can still be queried from API after purging history in Nextcloud talk — security-advisories 3.5 Low2023-04-17
CVE-2023-1831 User password logged in audit logs — Mattermost 7.2 High2023-04-17
CVE-2023-20866 Spring Session 安全漏洞 — Spring Session 6.5 -2023-04-13
CVE-2023-28271 Windows Kernel Memory Information Disclosure Vulnerability — Windows 10 Version 1809 5.5 Medium2023-04-11
CVE-2023-28221 Windows Error Reporting Service Elevation of Privilege Vulnerability — Windows 10 Version 1809 7.0 High2023-04-11
CVE-2022-43951 FortiNAC 安全漏洞 — FortiNAC 4.8 Medium2023-04-11

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.