Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-22276 free@home System Access Point FW integrity check can be bypassed. — System Access Point 6.1 Medium2021-09-23
CVE-2021-26333 AMD Chipset Driver Information Disclosure Vulnerability — PSP Driver 5.5 -2021-09-21
CVE-2021-41082 Private message title and participating users leaked in discourse — discourse 7.5 High2021-09-20
CVE-2021-24585 Timetable and Event Schedule by MotoPress < 2.4.0 - Arbitrary User's Hashed Password/Email/Username Disclosure — Timetable and Event Schedule by MotoPress 6.5 -2021-09-20
CVE-2021-40690 Bypass of the secureValidation property — Apache Santuario 7.5 -2021-09-19
CVE-2021-39327 BulletProof Security <= 5.1 Sensitive Information Disclosure — BulletProof Security 5.3 Medium2021-09-17
CVE-2021-39211 Disclosure of GLPI and server information in telemetry endpoint — glpi 5.3 Medium2021-09-15
CVE-2021-37192 Siemens SINEMA Remote Connect Server 信息泄露漏洞 — SINEMA Remote Connect Server 4.3 -2021-09-14
CVE-2021-37190 Siemens SINEMA Remote Connect Server 信息泄露漏洞 — SINEMA Remote Connect Server 4.3 -2021-09-14
CVE-2021-22527 Information leakage vulnerability in NetIQ Access Manager versions prior to version 4.5.4 and 5.0.1 — NetIQ Access Manager 6.0 Medium2021-09-13
CVE-2021-39203 Private data disclosure/privilege escalation through the block editor in Wordpress — wordpress-develop 6.8 Medium2021-09-09
CVE-2021-39200 Information Disclosure in wp_die() via JSONP in wordpress — wordpress-develop 5.3 Medium2021-09-09
CVE-2021-25464 Samsung SamsungCapture 信息泄露漏洞 — Samsung Capture 3.3 Low2021-09-09
CVE-2021-28566 Magento Commerce information disclosure during upload action leveraging a specially crafted file — Magento Commerce 3.7 Low2021-09-08
CVE-2021-37629 Lack of ratelimit on Richdocuments OCS endpoint in nextcloud — security-advisories 5.3 Medium2021-09-07
CVE-2020-7819 nTracker USB Enterprise SQL-Injection vulnerability — nTracker USB Enterprise 9.3 Critical2021-09-07
CVE-2021-36096 Support Bundle includes S/Mime and PGP secret or PIN — ((OTRS)) Community Edition 5.2 Medium2021-09-06
CVE-2021-36095 User enumeration issue using "lost password" feature — ((OTRS)) Community Edition 5.3 Medium2021-09-06
CVE-2021-39192 Privilege escalation: all users can access Admin-level API keys — Ghost 6.5 Medium2021-09-03
CVE-2021-38314 Gutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information Disclosure — Gutenberg Template Library & Redux Framework 5.3 Medium2021-09-02
CVE-2021-22793 Schneider Electric AccuSine PCS+和Schneider Electric AccuSine PCSn 信息泄露漏洞 — AccuSine PCS+ / PFV+ (Versions prior to V1.6.7) and AccuSine PCSn (Versions prior to V2.2.4) 8.8 -2021-09-02
CVE-2021-39164 Improper authorisation of /members discloses room membership to non-members — synapse 3.1 Low2021-08-31
CVE-2021-39163 Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner. — synapse 3.1 Low2021-08-31
CVE-2021-34749 Multiple Cisco Products Server Name Identification Data Exfiltration Vulnerability — Cisco Web Security Appliance (WSA) 5.8 Medium2021-08-18
CVE-2021-35936 No Authentication on Logging Server — Apache Airflow 5.3 -2021-08-16
CVE-2021-37703 Information exposure in Discourse — discourse 4.3 Medium2021-08-13
CVE-2021-37704 Exposed phpinfo() in PhpFastCache — phpfastcache 5.4 Medium2021-08-12
CVE-2021-21596 Dell OpenManage Enterprise 安全漏洞 — Dell OpenManage Enterprise 9.6 Critical2021-08-09
CVE-2021-21584 Dell OpenManage Enterprise 信息泄露漏洞 — Dell OpenManage Enterprise 7.7 High2021-08-09
CVE-2021-21564 Dell OpenManage Enterprise 授权问题漏洞 — Dell OpenManage Enterprise 9.8 Critical2021-08-09

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.