Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2723

2723 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-4823 Enter Software Iperius Backup NTLM2 information disclosure — Iperius Backup 2.5 Low2026-03-25
CVE-2025-14915 IBM WebSphere Application Server Liberty is affected by a privilege escalation vulnerability — WebSphere Application Server - Liberty 6.5 Medium2026-03-25
CVE-2026-33353 Soft Serve: Authenticated repo import can clone server-local private repositories — soft-serve 8.1 -2026-03-24
CVE-2026-33627 Parse Server: Auth data exposed via /users/me endpoint — parse-server 8.1 -2026-03-24
CVE-2026-33161 Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users — cms 5.4 -2026-03-24
CVE-2026-33677 Webhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API — vikunja 6.5 Medium2026-03-24
CVE-2026-4733 Information disclosure in ixray-1.6-stcop — ixray-1.6-stcop 5.3 Medium2026-03-24
CVE-2025-60949 Census CSWeb leaked configuration files — CSWeb 9.1 Critical2026-03-23
CVE-2026-23486 Blinko: Unauthorized User Information Leak — blinko 5.3 -2026-03-23
CVE-2026-27131 Sprig Plugin for Craft CMS potentially discloses sensitive information via Sprig Playground — craft-sprig 5.5 Medium2026-03-23
CVE-2025-13997 King Addons for Elementor <= 51.1.49 - Unauthenticated API Keys Disclosure — King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder 5.3 Medium2026-03-23
CVE-2026-33422 Discourse exposes ip_address of flagged user — discourse 3.5 Low2026-03-20
CVE-2026-33180 HAPI FHIR HTTP authentication leak in redirects — org.hl7.fhir.core 7.5 High2026-03-20
CVE-2026-33041 AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php — AVideo 5.3 Medium2026-03-20
CVE-2026-31869 Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check — discourse 4.3 -2026-03-20
CVE-2026-30891 Discourse hasUnauthorized Exposure of Private User Action Types — discourse 6.5 -2026-03-20
CVE-2026-29108 Authenticated SuiteCRM Users Can Retrieve The Password Hash of Any User — SuiteCRM-Core 6.5 Medium2026-03-19
CVE-2026-32002 OpenClaw < 2026.2.23 - Sandbox Boundary Bypass via Image Tool workspaceOnly Bypass — OpenClaw 5.3 Medium2026-03-19
CVE-2026-33394 Discourse leaks PM post edits to moderators — discourse 2.7 Low2026-03-19
CVE-2026-33355 Discourse filters whisper posts from private-posts feed — discourse 6.5 Medium2026-03-19
CVE-2026-32099 Discourse prevents hidden profile data leak via user onebox — discourse 4.3 Medium2026-03-19
CVE-2026-23659 Azure Data Factory Information Disclosure Vulnerability — Azure Data Factory 8.6 High2026-03-19
CVE-2026-32865 OPEXUS eComplaint and eCase insecure password reset — eComplaint 9.8 Critical2026-03-19
CVE-2026-2571 Download Manager <= 3.3.49 - Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter — Download Manager 4.3 Medium2026-03-19
CVE-2026-33163 Parse Server leaks protected fields via LiveQuery afterEvent trigger — parse-server 6.5 -2026-03-18
CVE-2026-32633 Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist` — glances 9.1 Critical2026-03-18
CVE-2026-32609 Glances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials — glances 7.5 High2026-03-18
CVE-2026-32596 Glances exposes the REST API without authentication — glances 9.1 -2026-03-18
CVE-2026-32266 Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability — google-cloud 5.3 -2026-03-18
CVE-2026-32265 Amazon S3 for Craft CMS has an Information Disclosure vulnerability — aws-s3 4.3 -2026-03-18

Vulnerabilities classified as CWE-200 (信息暴露) represent 2723 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.