CWE-200 信息暴露 类弱点 3396 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-200 指产品向未授权主体暴露敏感信息,属于信息泄露类漏洞。攻击者常通过未加密通信、错误日志记录或调试接口获取密钥、用户数据等机密内容。开发者应避免在日志中记录敏感字段,实施最小权限原则,对传输数据进行加密,并严格限制调试模式的访问权限,从而有效防止信息被非法窃取。
my $username=param('username'); my $password=param('password'); if (IsValidUsername($username) == 1) { if (IsValidPassword($username, $password) == 1) { print "Login Successful"; } else { print "Login Failed - incorrect password"; } } else { print "Login Failed - unknown username"; }
"Login Failed - incorrect username or password"
try { openDbConnection(); } //print exception message that includes exception message and configuration file location catch (Exception $e) { echo 'Caught exception: ', $e->getMessage(), '\n'; echo 'Check credentials in config file at: ', $Mysql_config_location, '\n'; }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-11961 | JeeWMS 访问控制错误漏洞 — Jeewms | 5.3 | Medium | 2024-11-28 |
| CVE-2024-53858 | GitHub CLI 信息泄露漏洞 — cli | 6.5 | Medium | 2024-11-27 |
| CVE-2024-53859 | go-gh 信息泄露漏洞 — go-gh | 6.5 | Medium | 2024-11-27 |
| CVE-2024-52323 | ZOHO ManageEngine Analytics Plus 安全漏洞 — Analytics Plus | 8.1 | High | 2024-11-27 |
| CVE-2024-11083 | WordPress plugin ProfilePress 信息泄露漏洞 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | 5.3 | Medium | 2024-11-27 |
| CVE-2017-18307 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2024-11-26 |
| CVE-2017-18306 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2024-11-26 |
| CVE-2024-8899 | WordPress plugin Jeg Elementor Kit 信息泄露漏洞 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | 4.3 | Medium | 2024-11-26 |
| CVE-2024-11265 | WordPress plugin Wp Maximum Upload File Size 信息泄露漏洞 — EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time | 4.3 | Medium | 2024-11-23 |
| CVE-2024-7391 | ChargePoint Home Flex 信息泄露漏洞 — Home Flex | 5.7 | - | 2024-11-22 |
| CVE-2024-8929 | PHP 安全漏洞 — PHP | 5.8 | Medium | 2024-11-22 |
| CVE-2024-11088 | WordPress plugin Simple Membership 安全漏洞 — Simple Membership | 5.3 | Medium | 2024-11-21 |
| CVE-2024-11089 | WordPress plugin Anonymous Restricted Content 安全漏洞 — Anonymous Restricted Content | 5.3 | Medium | 2024-11-21 |
| CVE-2024-9542 | WordPress plugin Sky Addons for Elementor 信息泄露漏洞 — Sky Addons – Elementor Addons with Widgets & Templates | 4.3 | Medium | 2024-11-21 |
| CVE-2024-10316 | WordPress plugin Stratum 信息泄露漏洞 — Stratum Widgets for Elementor | 4.3 | Medium | 2024-11-21 |
| CVE-2024-10365 | WordPress plugin The Plus Addons for Elementor 信息泄露漏洞 — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | 4.3 | Medium | 2024-11-20 |
| CVE-2024-52506 | Graylog 信息泄露漏洞 — graylog2-server | 4.3AI | Medium AI | 2024-11-18 |
| CVE-2024-43416 | GLPI 信息泄露漏洞 — glpi | 7.5 | High | 2024-11-18 |
| CVE-2020-3525 | Cisco Identity Services Engine 信息泄露漏洞 — Cisco Identity Services Engine Software | 4.9 | - | 2024-11-18 |
| CVE-2024-45791 | Apache HertzBeat 信息泄露漏洞 — Apache HertzBeat | 7.5AI | High AI | 2024-11-18 |
| CVE-2024-52508 | Nextcloud Mail 信息泄露漏洞 — security-advisories | 8.2 | High | 2024-11-15 |
| CVE-2024-52513 | Nextcloud 信息泄露漏洞 — security-advisories | 2.6 | Low | 2024-11-15 |
| CVE-2024-52517 | Nextcloud 信息泄露漏洞 — security-advisories | 4.6 | Medium | 2024-11-15 |
| CVE-2024-52523 | Nextcloud 信息泄露漏洞 — security-advisories | 4.6 | Medium | 2024-11-15 |
| CVE-2022-20648 | Cisco Redundancy Configuration Manager for Cisco StarOS 信息泄露漏洞 — Cisco Redundancy Configuration Manager | 5.3 | Medium | 2024-11-15 |
| CVE-2024-8978 | WordPress plugin Essential Addons for Elementor 安全漏洞 — Essential Addons for Elementor – Popular Elementor Templates & Widgets | 5.7 | Medium | 2024-11-15 |
| CVE-2024-8979 | WordPress plugin Essential Addons for Elementor 信息泄露漏洞 — Essential Addons for Elementor – Popular Elementor Templates & Widgets | 8.0 | High | 2024-11-15 |
| CVE-2024-47915 | VaeMendis Ubooquity 信息泄露漏洞 — VaeMendis Ubooquity version 2.1.2 | 7.5 | High | 2024-11-14 |
| CVE-2024-48900 | Moodle 信息泄露漏洞 | 4.3AI | Medium AI | 2024-11-13 |
| CVE-2024-52297 | Tolgee 安全漏洞 — tolgee-platform | 9.8 | Critical | 2024-11-12 |
CWE-200(信息暴露) 是常见的弱点类别,本平台收录该类弱点关联的 3396 条 CVE 漏洞。