Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-5601 Acrel Electrical Prepaid Cloud Platform Backup File bin.rar information disclosure — Prepaid Cloud Platform 5.3 Medium2026-04-05
CVE-2026-5585 Tencent AI-Infra-Guard Task Detail Endpoint task_manager.go information disclosure — AI-Infra-Guard 5.3 Medium2026-04-05
CVE-2026-5571 Technostrobe HI-LED-WR120-G2 Configuration Data fs information disclosure — HI-LED-WR120-G2 5.3 Medium2026-04-05
CVE-2026-34947 Discourse: Staged user custom fields are exposed on public invite pages — discourse 4.3AIMediumAI2026-04-03
CVE-2026-27481 Discourse: Hidden tag visibility bypass on tag routes — discourse 5.3AIMediumAI2026-04-03
CVE-2026-5413 Newgen OmniDocs GetWebApiConfiguration information disclosure — OmniDocs 3.7 Low2026-04-02
CVE-2026-5032 W3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header — W3 Total Cache 7.5 High2026-04-02
CVE-2026-34518 AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect — aiohttp 4.3 -2026-04-01
CVE-2026-3774 Self-Modifications Affecting Altered Printing and Redaction in Foxit PDF Editor — Foxit PDF Editor 4.7 Medium2026-04-01
CVE-2025-71280 XenForo Local Account Page Caching Information Disclosure — XenForo 6.2 Medium2026-04-01
CVE-2026-34215 Parse Server: Auth data exposed via verify password endpoint — parse-server 6.5 -2026-03-31
CVE-2026-33300 Discourse: Hidden group names and access metadata are exposed to moderators through the `category-chatables` endpoint — discourse 4.3 -2026-03-31
CVE-2026-32951 Discourse: Authorization bypass in oneboxer via user-controlled category id — discourse 4.3 Medium2026-03-31
CVE-2026-32620 Discourse: Missing post-level authorization allows whisper metadata disclosure — discourse 4.3 -2026-03-31
CVE-2026-32618 Discourse: Unauthorized channel membership inference via excluded_memberships_channel_id — discourse 4.3 Medium2026-03-31
CVE-2026-32143 Discourse: Admin-only report can be exported by moderators — discourse 6.5 -2026-03-31
CVE-2026-33073 discourse-subscriptions plugin leaking stripe API key in multisite environment — discourse 6.5 -2026-03-31
CVE-2026-4020 Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API — Gravity SMTP 7.5 High2026-03-31
CVE-2026-5003 PromtEngineer localGPT Web api_server.py handle_index information disclosure — localGPT 5.3 Medium2026-03-28
CVE-2026-1307 Ninja Forms <= 3.14.1 - Authenticated (Contributor+) Sensitive Information Disclosure via Block Editor Token — Ninja Forms – The Contact Form Builder That Grows With You 6.5 Medium2026-03-28
CVE-2026-33981 Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters — changedetection.io 7.5 -2026-03-27
CVE-2026-33886 Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields — cms 6.5 Medium2026-03-27
CVE-2026-31951 LibreChat's MCP Server Header Injection Enables OAuth Token Theft — LibreChat 6.8 Medium2026-03-27
CVE-2025-15381 Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow — mlflow/mlflow 5.4 -2026-03-27
CVE-2025-59031 Open-Xchange OX Dovecot Pro 安全漏洞 — OX Dovecot Pro 4.3 Medium2026-03-27
CVE-2026-33745 cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect — cpp-httplib 7.4 High2026-03-27
CVE-2026-1556 Information disclosure via file URI overwrite in File (Field) Paths — Drupal File (Field) Paths 6.5 -2026-03-26
CVE-2025-55265 HCL Aftermarket DPC is affected by File Discovery — Aftermarket DPC 6.5 Medium2026-03-26
CVE-2025-55272 HCL Aftermarket DPC is affected by Banner Disclosure vulnerability — Aftermarket DPC 3.1 Low2026-03-26
CVE-2025-55276 HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability — Aftermarket DPC 3.1 Low2026-03-26

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.