Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-0281 Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber — microweber/microweber 7.5 -2022-01-20
CVE-2022-22733 Access-Token in ElasticJob UI causes password disclosure — Apache ShardingSphere ElasticJob-UI 8.1 -2022-01-20
CVE-2022-21673 OAuth Identity Token exposure in Grafana — grafana 4.3 Medium2022-01-18
CVE-2022-21683 Comment reply notifications sent to incorrect users in wagtail — wagtail 3.5 Low2022-01-18
CVE-2021-37867 Emails of all users are exposed via one of the Boards APIs — Mattermost Boards 4.3 Medium2022-01-18
CVE-2022-0235 Exposure of Sensitive Information to an Unauthorized Actor in node-fetch/node-fetch — node-fetch/node-fetch 7.1 -2022-01-16
CVE-2021-44739 Adobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) src NTLMv2 SSO Auth leak vulnerability — Acrobat Reader 4.3 -2022-01-14
CVE-2021-44702 Adobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) for Internet Explorer LoadFile NTLMv2 SSO Auth leak vulnerability — Acrobat Reader 4.3 -2022-01-14
CVE-2022-21677 Group advanced search option may leak group and group's members visibility — discourse 4.3 Medium2022-01-14
CVE-2022-21678 User's bio visible even if profile is restricted in Discourse — discourse 4.3 Medium2022-01-13
CVE-2021-41767 Private tunnel identifier may be included in the non-private details of active connections — Apache Guacamole 6.5 -2022-01-11
CVE-2022-21671 Potential exposure of Replit tokens to an Unauthorized Actor in @replit/crosis — crosis 8.1 High2022-01-11
CVE-2021-24948 The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosure — The Plus Addons for Elementor - Pro 7.5 -2022-01-10
CVE-2022-21642 Exposure of whisper participants in discourse — discourse 4.3 Medium2022-01-05
CVE-2021-4024 Podman 访问控制错误漏洞 — podman 6.5 -2021-12-23
CVE-2021-36341 Dell Wyse Device Agent 信息泄露漏洞 — Dell Wyse Device Agent 5.5 Medium2021-12-21
CVE-2021-43823 Side-channel attack in Sourcegraph — sourcegraph 6.5 Medium2021-12-13
CVE-2021-24945 Like Button Rating < 2.6.38 - Unauthorised Vote Export to Email & IP Addresses Disclosure — Like Button Rating ♥ LikeBtn 6.5 -2021-12-13
CVE-2021-41090 Instance config inline secret exposure — agent 6.5 Medium2021-12-08
CVE-2021-25519 Samsung CPLC 安全漏洞 — Samsung Mobile Devices 4.0 Medium2021-12-08
CVE-2021-29115 An information disclosure vulnerability — ArcGIS Server 5.3 -2021-12-07
CVE-2021-36198 Entrapass — Entrapass 8.3 High2021-12-06
CVE-2021-43792 Notifications leak in Discourse — discourse 4.3 Medium2021-12-01
CVE-2019-5640 Rapid7 Nexpose Information Disclosure after logout — Nexpose 3.3 Low2021-11-22
CVE-2021-41532 Unauthenticated access to Ozone Recon HTTP endpoints — Apache Ozone 5.3 -2021-11-19
CVE-2021-23193 Gallagher Command Centre Server 信息泄露漏洞 — Command Centre 8.1 High2021-11-18
CVE-2021-37939 Elastic Stack Kibana 安全漏洞 — Kibana 2.7 -2021-11-18
CVE-2021-41277 GeoJSON URL validation can expose server files and environment variables to unauthorized users — metabase 10.0 Critical2021-11-17
CVE-2021-41271 Cache poisoning via maliciously-formed request in discourse — discourse 4.8 Medium2021-11-15
CVE-2021-41263 Secure/signed cookies share secrets between sites in rails_multisite — rails_multisite 8.3 High2021-11-15

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.