Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-41251 Possibility to elevate privileges or get unauthorized access to data — cloud-sdk-js 5.9 Medium2021-11-05
CVE-2021-34774 Cisco Common Services Platform Collector Information Disclosure Vulnerability — Cisco Common Services Platform Collector Software 4.9 Medium2021-11-04
CVE-2021-22047 VMware Spring Security 安全漏洞 — Spring Data REST 5.3 -2021-10-28
CVE-2021-22044 Spring Cloud OpenFeign 安全漏洞 — Spring Cloud OpenFeign 9.1 -2021-10-28
CVE-2021-41158 FreeSWITCH vulnerable to SIP digest leak for configured gateways — freeswitch 5.8 Medium2021-10-26
CVE-2021-39224 File path disclosure of shared files in OfficeOnline application — security-advisories 3.5 Low2021-10-25
CVE-2021-39223 File path disclosure of shared files in Richdocuments application — security-advisories 4.8 Medium2021-10-25
CVE-2017-20007 Information Exposure in INGEPAC DA AU — INGEPAC DA AU 5.3 Medium2021-10-25
CVE-2021-42536 Emerson WirelessHART Gateway — WirelessHART Gateway 8.0 High2021-10-22
CVE-2021-31371 Junos OS: QFX5000 Series: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces. — Junos OS 5.3 Medium2021-10-19
CVE-2021-31352 SRC Series: NETCONF over SSH allows negotiation of weak ciphers — SRC Series 5.3 Medium2021-10-19
CVE-2021-33727 Siemens SINEC NMS 信息泄露漏洞 — SINEC NMS 6.5 -2021-10-12
CVE-2021-32028 PostgreSQL 信息泄露漏洞 — postgresql 6.5 -2021-10-11
CVE-2021-32029 PostgreSQL 缓冲区错误漏洞 — postgresql 6.5 -2021-10-08
CVE-2021-34702 Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability — Cisco Identity Services Engine Software 4.3 Medium2021-10-06
CVE-2021-41125 HTTP authentication credential leak to target websites in scrapy — scrapy 5.7 Medium2021-10-06
CVE-2021-25486 Samsung SMR 信息泄露漏洞 — Samsung Mobile Devices 2.5 Low2021-10-06
CVE-2021-41124 Splash authentication credentials potentially leaked to target websites in scrapy-splash — scrapy-splash 7.4 High2021-10-05
CVE-2021-41120 Unauthorized access to Credit card form in sylius/paypal-plugin — PayPalPlugin 7.5 High2021-10-05
CVE-2021-41123 Exposure of Sensitive Information to an Unauthorized Actor in WB.UI.Headquarters.dll — surveysolutions 5.3 Medium2021-10-04
CVE-2021-41092 Docker CLI leaks private registry credentials to registry-1.docker.io — cli 5.4 Medium2021-10-04
CVE-2021-23855 Information disclosure — IndraMotion MLC IndraMotion XLC 8.6 High2021-10-04
CVE-2021-23858 Information disclosure — IndraMotion MLC L25, L45, L65, L75, L85, XM21, XM22, XM41 and XM42 IndraControl XLC 8.6 High2021-10-04
CVE-2021-41109 LiveQuery publishes user session tokens — parse-server 7.5 High2021-09-30
CVE-2021-41301 ECOA BAS controller - Exposure of Sensitive Information to an Unauthorized Actor — ECS Router Controller ECS (FLASH) 9.8 Critical2021-09-30
CVE-2021-39856 Adobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via LoadFile — Acrobat Reader 6.5 Medium2021-09-29
CVE-2021-39855 Adobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via src Parameter — Acrobat Reader 6.5 Medium2021-09-29
CVE-2021-39857 Adobe Acrobat Reader DC Information Disclosure via ActiveX LoadFile — Acrobat Reader 4.3 -2021-09-29
CVE-2021-24661 PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Private Content Disclosure — PostX – Gutenberg Blocks for Post Grid 4.3 -2021-09-27
CVE-2021-22272 ControlTouch Cloud Service vulnerability: Serial Number can be misused during commissioning phase. — mybuildings.abb.com 6.5 Medium2021-09-27

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.