CWE-497 将系统数据暴露到未授权控制的范围 类弱点 379 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-497属于敏感信息泄露漏洞,指产品未能阻止未授权方访问底层系统信息。攻击者常利用网络通信中的错误响应或调试信息,获取操作系统、数据库配置等敏感细节,进而辅助后续攻击。开发者应严格限制错误信息的输出,确保仅返回必要的业务数据,并实施最小权限原则,防止敏感系统细节暴露给外部不可信实体。
char* path = getenv("PATH"); ... sprintf(stderr, "cannot find exe on path %s\n", path);
//assume getCurrentUser() returns a username that is guaranteed to be alphanumeric (avoiding CWE-78) $userName = getCurrentUser(); $command = 'ps aux | grep ' . $userName; system($command);
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-62036 | WordPress All Bootstrap Blocks <=1.3.31 敏感数据泄露漏洞 — All Bootstrap Blocks | 4.3 | Medium | 2026-10-09 |
| CVE-2026-102387 | WordPress Xserver Migrator <= 1.6.6 敏感数据泄露漏洞 — Xserver Migrator | 7.5 | High | 2026-10-06 |
| CVE-2026-105073 | WordPress WP Event Solution <= 4.1.25 敏感信息泄露漏洞 — WP Event Solution | 5.3 | Medium | 2026-10-05 |
| CVE-2026-104401 | WordPress Memberful插件<=1.81.2敏感数据暴露漏洞 — Memberful - Membership Plugin | 4.3 | Medium | 2026-10-05 |
| CVE-2026-97181 | ezGlobal GPM LIGHT 敏感数据泄露漏洞 — GPM LIGHT | 5.3 | Medium | 2026-09-24 |
| CVE-2026-84712 | Automation-controller 未授权 API 漏洞暴露实例拓扑与成员信息 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 | 5.3 | Medium | 2026-09-23 |
| CVE-2026-95600 | WordPress插件敏感数据暴露漏洞 — TrustedLogin Connector | 5.3 | Medium | 2026-09-23 |
| CVE-2025-33141 | IBM QRadar SIEM 备份文件信息泄露漏洞 — QRadar | 6.5 | Medium | 2026-09-18 |
| CVE-2026-27553 | 模式路径操作信息泄露 — ICE2-8IOL1-G65L-V1D | 6.5 | Medium | 2026-09-16 |
| CVE-2026-38058 | ST Engineering iDirect Evolution iQ‑Series terminals 信息泄露漏洞 — Evolution iQ‑Series terminals | 8.1 | High | 2026-09-11 |
| CVE-2026-61911 | The Cyrus Team Cyrus IMAP 信息泄露漏洞 — Cyrus IMAP | 4.3 | Medium | 2026-09-09 |
| CVE-2026-81394 | Microsoft Office Excel 信息泄露漏洞 — Microsoft 365 Apps for Enterprise | 5.5 | Medium | 2026-09-08 |
| CVE-2026-81387 | Microsoft Office Excel 信息泄露漏洞 — Microsoft 365 Apps for Enterprise | 5.5 | Medium | 2026-09-08 |
| CVE-2026-69315 | Microsoft Windows License Manager 信息泄露漏洞 — Windows 10 Version 1809 | 5.5 | Medium | 2026-09-08 |
| CVE-2026-68842 | Microsoft Windows MIDI Service Module 信息泄露漏洞 — Windows 11 Version 24H2 | 5.5 | Medium | 2026-09-08 |
| CVE-2026-71330 | Microsoft Windows Services 信息泄露漏洞 — Windows 10 Version 1607 | 7.5 | High | 2026-09-08 |
| CVE-2026-69832 | Microsoft Win32K 信息泄露漏洞 — Windows 10 Version 1607 | 5.6 | Medium | 2026-09-08 |
| CVE-2026-69723 | Microsoft Windows Kernel 信息泄露漏洞 — Windows 10 Version 1607 | 5.7 | Medium | 2026-09-08 |
| CVE-2026-69406 | Microsoft Windows Kernel 信息泄露漏洞 — Windows 10 Version 1607 | 5.5 | Medium | 2026-09-08 |
| CVE-2026-69339 | Microsoft Windows MIDI Service Module 信息泄露漏洞 — Windows 11 Version 24H2 | 5.5 | Medium | 2026-09-08 |
| CVE-2026-16006 | ASUS Armoury Crate 信息泄露漏洞 — Armoury Crate | 5.7 | Medium | 2026-09-08 |
| CVE-2026-76968 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server 信息泄露漏洞 — SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 6.5 | Medium | 2026-09-08 |
| CVE-2026-66840 | XING CPTrans-ME-X 信息泄露漏洞 — XING CPTrans-ME-X | 8.7 | High | 2026-09-04 |
| CVE-2026-81774 | WordPress WooCommerce Product Attachment 信息泄露漏洞 — WooCommerce Product Attachment | 7.5 | High | 2026-09-02 |
| CVE-2026-53682 | Dogtag PKI 信息泄露漏洞 — Red Hat Certificate System 9 | 5.3 | Medium | 2026-09-01 |
| CVE-2026-78268 | WordPress SiteLeads 信息泄露漏洞 — Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads | 7.5 | High | 2026-08-24 |
| CVE-2026-75928 | Brushfire Online Experience 信息泄露漏洞 — Online Experience | 5.3 | Medium | 2026-08-21 |
| CVE-2026-67267 | Dell Command Update 信息泄露漏洞 — Dell Command Update (DCU) | 5.5 | Medium | 2026-08-19 |
| CVE-2026-74007 | iberezansky 3D FlipBook 信息泄露漏洞 — 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery | 5.3 | Medium | 2026-08-18 |
| CVE-2026-32468 | rayhanduitku Duitku Payment Gateway 信息泄露漏洞 — Duitku Payment Gateway | 7.5 | High | 2026-08-18 |
CWE-497(将系统数据暴露到未授权控制的范围) 是常见的弱点类别,本平台收录该类弱点关联的 379 条 CVE 漏洞。