Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-200 (信息暴露) — Vulnerability Class 2722

2722 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-28506 Outline's Information Disclosure in Activity Logs allows User Enumeration of Private Drafts — outline 4.3 Medium2026-03-17
CVE-2026-2476 MS Teams plugin sensitive config values not properly masked in support packets — Mattermost 7.6 High2026-03-16
CVE-2026-4218 myAEDES App aedes.me.beta EngageBayUtils.java information disclosure — myAEDES App 2.5 Low2026-03-16
CVE-2026-22203 wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext — wpDiscuz 4.9 Medium2026-03-13
CVE-2026-32237 @backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint — plugin-scaffolder-backend 4.4 Medium2026-03-12
CVE-2026-32142 shopware/commercial: `/api/_info/config` route exposes information about licenses — commercial 5.3 Medium2026-03-12
CVE-2026-32100 swag/platform-security: `/api/_info/config` route exposes information about licenses and active security fixes — platform-security 5.3 Medium2026-03-12
CVE-2026-32098 Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause — parse-server 7.5AIHighAI2026-03-11
CVE-2026-32094 Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash — shescape 7.5AIHighAI2026-03-11
CVE-2026-20166 Sensitive Information Disclosure in Discover Splunk Observability Cloud app for Splunk Enterprise — Splunk Enterprise 5.4 Medium2026-03-11
CVE-2026-20164 Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise — Splunk Enterprise 6.5 Medium2026-03-11
CVE-2026-31837 Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch fails. — istio 9.8AICriticalAI2026-03-10
CVE-2025-66413 Git for Windows leaks NTLM hash when cloning from an attacker-controlled server — git 7.4 High2026-03-10
CVE-2026-25185 Windows Shell Link Processing Spoofing Vulnerability — Windows 10 Version 1607 5.3 Medium2026-03-10
CVE-2026-25186 Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2026-03-10
CVE-2026-30928 Glances Exposes Unauthenticated Configuration Secrets — glances 9.1AICriticalAI2026-03-10
CVE-2026-30933 FileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info — filebrowser 7.5 High2026-03-10
CVE-2026-30852 Caddy: vars_regexp double-expands user input, leaking env vars and files — caddy 9.1 -2026-03-07
CVE-2026-29787 mcp-memory-service: System Information Disclosure via Health Endpoint — mcp-memory-service 5.3 Medium2026-03-07
CVE-2026-29779 UptimeFlare: Montior config / Credentials in `workerConfig` exposed in client-side JavaScript bundle — UptimeFlare 7.5 High2026-03-07
CVE-2026-27796 Homarr: Unauthenticated Information Disclosure (Integration Metadata Leak) — homarr 5.3 Medium2026-03-07
CVE-2026-30829 Checkmate: Unauthenticated Access to Unpublished Status Page — Checkmate 5.3 Medium2026-03-07
CVE-2026-30233 OliveTin: View permission not being checked when returning dashboards — OliveTin 6.5 Medium2026-03-06
CVE-2026-30847 Wekan Credential Leak via notificationUsers Publication Exposes Password Hashes and Session Tokens — Wekan 6.5 -2026-03-06
CVE-2026-30845 Wekan Exposes Sensitive Data through Lack of Field Filtering During Board Publication — Wekan 7.5 -2026-03-06
CVE-2026-28675 OpenSift: Sensitive implementation details exposed via raw exception messages and token-returning endpoints — OpenSift 5.3 Medium2026-03-06
CVE-2026-2589 Greenshift – animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup — Greenshift – animation and page builder blocks 5.3 Medium2026-03-05
CVE-2026-28492 File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory — filebrowser 8.1 -2026-03-05
CVE-2025-68467 Dark Reader gives users the ability to request style sheets from local web servers — darkreader 3.4 Low2026-03-04
CVE-2026-28434 cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header — cpp-httplib 5.3 Medium2026-03-04

Vulnerabilities classified as CWE-200 (信息暴露) represent 2722 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.