2779 vulnerabilities classified as CWE-200 (信息暴露). AI Chinese analysis included.
CWE-200 represents a critical information disclosure weakness where software inadvertently reveals sensitive data to unauthorized entities. This vulnerability is typically exploited by attackers who leverage insufficient access controls, insecure direct object references, or verbose error messages to harvest credentials, personal identifiable information, or internal system details. By analyzing network traffic or manipulating application inputs, adversaries can extract this exposed data to facilitate further attacks, such as identity theft or privilege escalation. To mitigate this risk, developers must implement strict access control mechanisms, ensuring that data retrieval is validated against user permissions. Additionally, employing robust encryption for data at rest and in transit, along with sanitizing error outputs to prevent information leakage, significantly reduces the attack surface. Regular security audits and adherence to the principle of least privilege further ensure that sensitive information remains protected from unauthorized exposure.
my $username=param('username'); my $password=param('password'); if (IsValidUsername($username) == 1) { if (IsValidPassword($username, $password) == 1) { print "Login Successful"; } else { print "Login Failed - incorrect password"; } } else { print "Login Failed - unknown username"; }"Login Failed - incorrect username or password"try { openDbConnection(); } //print exception message that includes exception message and configuration file location catch (Exception $e) { echo 'Caught exception: ', $e->getMessage(), '\n'; echo 'Check credentials in config file at: ', $Mysql_config_location, '\n'; }| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-25118 | Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosure — Yoast SEO | 5.3 | - | 2022-02-28 |
| CVE-2022-0654 | Exposure of Sensitive Information to an Unauthorized Actor in fgribreau/node-request-retry — fgribreau/node-request-retry | 7.5 | - | 2022-02-22 |
| CVE-2022-23984 | WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosure — Comments – wpDiscuz (WordPress plugin) | 3.7 | Low | 2022-02-21 |
| CVE-2022-0708 | Team Creator's Email Address is disclosed to Team Members via one of the APIs — Mattermost | 4.3 | Medium | 2022-02-21 |
| CVE-2021-44141 | samba 后置链接漏洞 — Samba | 4.3 | - | 2022-02-21 |
| CVE-2021-20320 | Linux kernel 安全漏洞 — kernel | 5.5 | - | 2022-02-18 |
| CVE-2022-0672 | Red Hat Vscode-Xml 信息泄露漏洞 — LemMinX | 5.0 | - | 2022-02-18 |
| CVE-2022-23982 | WordPress Perfect Brands for WooCommerce plugin <= 2.0.4 - Server Information Exposure vulnerability — Perfect Brands for WooCommerce (WordPress plugin) | 4.3 | Medium | 2022-02-18 |
| CVE-2021-3773 | netfilter 信息泄露漏洞 — kernel | 9.8 | - | 2022-02-16 |
| CVE-2022-23643 | Side-channel attack in Sourcegraph Code Monitors — sourcegraph | 6.5 | Medium | 2022-02-15 |
| CVE-2021-25110 | Futurio Extra < 1.6.3 - Subscriber+ User Email Address Disclosure — Futurio Extra | 4.3 | - | 2022-02-14 |
| CVE-2022-23634 | Information Exposure when using Puma with Rails — puma | 8.0 | High | 2022-02-11 |
| CVE-2021-22785 | Schneider Electric 多款产品信息泄露漏洞 — Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H), BMXNOE0110 (H), BMXNOC0401, BMXNOR0200H RTU (All Versions), Modicon Premium Processors with integrated Ethernet (Copro): TSXP574634, TSXP575634, TSXP576634 (All Versions), Modicon Quantum Processors with Integrated Ethernet (Copro): 140CPU65xxxxx (All Versions), Modicon Quantum Communication Modules: 140NOE771x1, 140NOC78x00, 140NOC77101 (All Versions), Modicon Premium Communication Modules: TSXETY4103, TSXETY5103 (All Versions) | 7.5 | - | 2022-02-11 |
| CVE-2022-24003 | Samsung Bixby Vision 信息泄露漏洞 — Bixby Vision | 4.0 | Medium | 2022-02-11 |
| CVE-2022-24001 | Google Android 信息泄露漏洞 — Samsung Mobile Devices | 3.8 | Low | 2022-02-11 |
| CVE-2022-23633 | Exposure of sensitive information in Action Pack — rails | 7.4 | High | 2022-02-11 |
| CVE-2022-20680 | Cisco Prime Service Catalog Information Disclosure Vulnerability — Cisco Prime Service Catalog | 4.3 | Medium | 2022-02-10 |
| CVE-2022-20630 | Cisco DNA Center Information Disclosure Vulnerability — Cisco Digital Network Architecture Center (DNA Center) | 4.4 | Medium | 2022-02-10 |
| CVE-2022-22545 | SAP NetWeaver Application Server 信息泄露漏洞 — SAP NetWeaver Application Server ABAP and ABAP Platform | 4.9 | - | 2022-02-09 |
| CVE-2022-22542 | Sap Crm Web Channel 信息泄露漏洞 — SAP S/4HANA (Supplier Factsheet and Enterprise Search for Business Partner, Supplier and Customer) | 6.5 | - | 2022-02-09 |
| CVE-2022-23619 | Information exposure in xwiki-platform — xwiki-platform | 5.3 | Medium | 2022-02-09 |
| CVE-2021-40360 | Siemens SIMATIC 信息泄露漏洞 — SIMATIC PCS 7 V8.2 | 7.8 | - | 2022-02-09 |
| CVE-2022-0474 | Disclosure of mail addresses — OTRSCustomContactFields | 2.4 | Low | 2022-02-07 |
| CVE-2022-22680 | Synology DiskStation Manager 信息泄露漏洞 — DiskStation Manager (DSM) | 5.3 | Medium | 2022-02-07 |
| CVE-2022-21712 | Cookie and header exposure in twisted — twisted | 7.5 | High | 2022-02-07 |
| CVE-2022-23607 | Unsafe handling of user-specified cookies in treq — treq | 6.5 | Medium | 2022-02-01 |
| CVE-2022-0281 | Exposure of Sensitive Information to an Unauthorized Actor in microweber/microweber — microweber/microweber | 7.5 | - | 2022-01-20 |
| CVE-2022-22733 | Access-Token in ElasticJob UI causes password disclosure — Apache ShardingSphere ElasticJob-UI | 8.1 | - | 2022-01-20 |
| CVE-2022-21673 | OAuth Identity Token exposure in Grafana — grafana | 4.3 | Medium | 2022-01-18 |
| CVE-2022-21683 | Comment reply notifications sent to incorrect users in wagtail — wagtail | 3.5 | Low | 2022-01-18 |
Vulnerabilities classified as CWE-200 (信息暴露) represent 2779 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.