Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2722

2722 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-33829 Windows Snipping Tool Spoofing Vulnerability — Windows 10 Version 1607 4.3 Medium2026-04-14
CVE-2026-32151 Windows Shell Information Disclosure Vulnerability — Windows 10 Version 1607 6.5 Medium2026-04-14
CVE-2026-32084 Windows Print Spooler Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2026-04-14
CVE-2026-32079 Web Account Manager Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2026-04-14
CVE-2026-32085 Remote Procedure Call Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2026-04-14
CVE-2026-32081 Package Catalog Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2026-04-14
CVE-2024-23104 Fortinet FortiNDR 信息泄露漏洞 — FortiVoice 5.4 Medium2026-04-14
CVE-2026-34984 External Secrets Operator has DNS exfiltration via getHostByName in its v2 template engine — external-secrets 7.2 -2026-04-14
CVE-2026-32270 Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments — commerce 5.3 -2026-04-13
CVE-2026-3691 OpenClaw Client PKCE Verifier Information Disclosure Vulnerability — OpenClaw 6.5AIMediumAI2026-04-11
CVE-2026-40159 PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution — PraisonAI 5.5 Medium2026-04-10
CVE-2026-6000 code-projects Online Library Management System SQL Database Backup File library.sql information disclosure — Online Library Management System 4.3 Medium2026-04-10
CVE-2026-40151 PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS — PraisonAI 5.3 Medium2026-04-09
CVE-2026-39943 Directus exposes sensitive fields in revision history — directus 6.5 Medium2026-04-09
CVE-2026-5960 code-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclosure — Patient Record Management System 4.3 Medium2026-04-09
CVE-2026-4660 Go-getter may allow to arbitrary filesystem reads through git operations — Tooling 7.5 High2026-04-09
CVE-2025-62188 Apache DolphinScheduler: Users can access sensitive information through the actuator endpoint. — Apache DolphinScheduler 7.5AIHighAI2026-04-09
CVE-2026-5847 code-projects Movie Ticketing System SQL Database Backup File moviedb.sql information disclosure — Movie Ticketing System 4.3 Medium2026-04-09
CVE-2026-39889 PraisonAI has Unauthenticated SSE Event Stream Exposes All Agent Activity in A2U Server — PraisonAI 7.5 High2026-04-08
CVE-2026-39412 LiquidJS has an ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel — liquidjs 5.3 Medium2026-04-08
CVE-2026-3594 Riaxe Product Customizer <= 2.4 - Unauthenticated Sensitive Information Disclosure via '/orders' REST API Endpoint — Riaxe Product Customizer 5.3 Medium2026-04-08
CVE-2026-27949 Plane Exposes User Email (PII and part of credential) in GET Parameter — plane 2.0 Low2026-04-07
CVE-2026-39363 Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket — vite 7.5 -2026-04-07
CVE-2026-5375 runZero Platform API credential information leak — Platform 2.7 Low2026-04-07
CVE-2026-35452 WWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php — AVideo 5.3 Medium2026-04-06
CVE-2026-35449 WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php — AVideo 5.3 Medium2026-04-06
CVE-2026-35442 Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries — directus 8.1 High2026-04-06
CVE-2026-35413 Directus GraphQL Schema SDL Disclosure Setting — directus 5.3 Medium2026-04-06
CVE-2026-34969 Nhost Leaks the Refresh Token via URL Query Parameter in OAuth Provider Callback — nhost 5.3AIMediumAI2026-04-06
CVE-2026-5601 Acrel Electrical Prepaid Cloud Platform Backup File bin.rar information disclosure — Prepaid Cloud Platform 5.3 Medium2026-04-05

Vulnerabilities classified as CWE-200 (信息暴露) represent 2722 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.