CWE-200 · 10.849 kayıt
Hassas bilginin yetkisiz kişiye ifşası
Neden olur?
Eklenti işlevi için gerekenden geniş izin istiyor ve topladığı veriyi amacı dışında dışarı gönderiyor.
Hatalı ve düzeltilmiş kod
Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.
Hatalı
{ "permissions": ["tabs", "<all_urls>"], "background": { "service_worker": "analytics.js" }}Düzeltilmiş
{ "permissions": ["activeTab"], "host_permissions": ["https://yildiz.example/*"]}Nasıl önlenir?
- 01Yalnızca işlevin gerektirdiği izinleri isteyin.
- 02Toplanan veriyi açıkça belgeleyin ve en aza indirin.
- 03Kurumsal tarayıcılarda eklentileri izin listesiyle yönetin.
Bu sınıftaki CVE’ler
10.000 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
94Hemen | CVE-2024-24919Silahlaştırılmış | Information disclosurecheckpoint · quantum spark firmware · CWE-200 | Yüksek8,6 | KEV | %100,0 | 28 May 2024 |
89Hemen | CVE-2021-41277Silahlaştırılmış | GeoJSON URL validation can expose server files and environment variables to unauthorized usersmetabase · metabase · CWE-200 | Yüksek7,5 | KEV | %97,2 | 17 Kas 2021 |
86Hemen | CVE-2016-6415Silahlaştırılmış | The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5cisco · ios · CWE-200 | Yüksek7,5 | KEV | %87,7 | 18 Eyl 2016 |
85Hemen | CVE-2023-28432Silahlaştırılmış | Minio Information Disclosure in Cluster Deploymentminio · minio · CWE-200 | Yüksek7,5 | KEV | %84,0 | 22 Mar 2023 |
84Hemen | CVE-2023-49103Silahlaştırılmış | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.owncloud · graph api · CWE-200 | Yüksek7,5 | KEV | %78,4 | 21 Kas 2023 |
82Hemen | CVE-2020-3259Silahlaştırılmış | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerabilitycisco · secure firewall threat defense · CWE-200 | Yüksek7,5 | KEV | %71,8 | 6 May 2020 |
79Bu hafta | CVE-2025-31125Silahlaştırılmış | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` queryvitejs · vite · CWE-200 | Yüksek7,5 | KEV | %64,7 | 31 Mar 2025 |
76Bu hafta | CVE-2008-0655Silahlaştırılmış | Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.adobe · acrobat · CWE-200 | Yüksek8,8 | KEV | %37,9 | 7 Şub 2008 |
70Bu hafta | CVE-2026-20133Silahlaştırılmış | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affectcisco · catalyst sd-wan manager · CWE-200 | Yüksek7,5 | KEV | %31,8 | 25 Şub 2026 |
67Bu hafta | CVE-2021-27850Silahlaştırılmış | Bypass of the fix for CVE-2019-0195apache · tapestry · CWE-200 | Kritik9,8 | — | %93,5 | 15 Nis 2021 |
67Bu hafta | CVE-2016-2388Silahlaştırılmış | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a craftedsap · netweaver application server java · CWE-200 | Orta5,3 | KEV | %52,2 | 16 Şub 2016 |
67Bu hafta | CVE-2015-5317Silahlaştırılmış | The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name injenkins · jenkins · CWE-200 | Yüksek7,5 | KEV | %23,0 | 25 Kas 2015 |
66Bu hafta | CVE-2015-0310Silahlaştırılmış | Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not padobe · flash player · CWE-200 | Yüksek7,8 | KEV | %15,1 | 23 Oca 2015 |
62Bu hafta | CVE-2018-1000600Kavram kanıtı | A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java tjenkins · github · CWE-200 | Yüksek8,8 | — | %90,9 | 26 Haz 2018 |
62Bu hafta | CVE-2018-0127Kavram kanıtı | A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allocisco · rv132w firmware · CWE-200 | Kritik9,8 | — | %77,5 | 8 Şub 2018 |
62Bu hafta | CVE-2025-68686Silahlaştırılmış | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,fortinet · fortios · CWE-200 | Orta5,9 | KEV | %29,6 | 10 Şub 2026 |
61Bu hafta | CVE-2025-11749Silahlaştırılmış | AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalationtigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress · CWE-200 | Kritik9,8 | — | %74,8 | 5 Kas 2025 |
61Bu hafta | CVE-2018-7251Kavram kanıtı | An issue was discovered in config/error.php in Anchor 0.12.3.anchorcms · anchor · CWE-200 | Kritik9,8 | — | %71,8 | 19 Şub 2018 |
59Planlayın | CVE-2022-20821Silahlaştırılmış | Cisco IOS XR Software Health Check Open Port Vulnerabilitycisco · ios xr · CWE-200 | Orta6,5 | KEV | %11,5 | 26 May 2022 |
58Planlayın | CVE-2016-2183Kavram kanıtı | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | Yüksek7,5 | — | %94,7 | 31 Ağu 2016 |
58Planlayın | CVE-2016-10175Silahlaştırılmış | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI.netgear · wnr2000v5 firmware · CWE-200 | Kritik9,8 | — | %65,0 | 30 Oca 2017 |
58Planlayın | CVE-2017-11165Kavram kanıtı | dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for ththermofisher · dt80 dex firmware · CWE-200 | Kritik9,8 | — | %63,9 | 12 Tem 2017 |
57Planlayın | CVE-2011-3497Silahlaştırılmış | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibmeasuresoft · scadapro · CWE-200 | Kritik10,0 | — | %57,1 | 16 Eyl 2011 |
56Planlayın | CVE-2017-16894Silahlaştırılmış | In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct relaravel · laravel · CWE-200 | Yüksek7,5 | — | %86,9 | 19 Kas 2017 |
56Planlayın | CVE-2018-4993Silahlaştırılmış | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO haadobe · acrobat dc · CWE-200 | Yüksek7,5 | — | %86,7 | 9 Tem 2018 |
- CVE-2024-2491994Hemen
Information disclosure
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %100checkpoint · quantum spark firmware28 May 2024
- CVE-2021-4127789Hemen
GeoJSON URL validation can expose server files and environment variables to unauthorized users
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %97metabase · metabase17 Kas 2021
- CVE-2016-641586Hemen
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %88cisco · ios18 Eyl 2016
- CVE-2023-2843285Hemen
Minio Information Disclosure in Cluster Deployment
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %84minio · minio22 Mar 2023
- CVE-2023-4910384Hemen
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %78owncloud · graph api21 Kas 2023
- CVE-2020-325982Hemen
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %72cisco · secure firewall threat defense6 May 2020
- CVE-2025-3112579Bu hafta
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %65vitejs · vite31 Mar 2025
- CVE-2008-065576Bu hafta
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %38adobe · acrobat7 Şub 2008
- CVE-2026-2013370Bu hafta
A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affect
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %32cisco · catalyst sd-wan manager25 Şub 2026
- CVE-2021-2785067Bu hafta
Bypass of the fix for CVE-2019-0195
KritikCVSS 9,8SilahlaştırılmışEPSS %93apache · tapestry15 Nis 2021
- CVE-2016-238867Bu hafta
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %52sap · netweaver application server java16 Şub 2016
- CVE-2015-531767Bu hafta
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name in
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %23jenkins · jenkins25 Kas 2015
- CVE-2015-031066Bu hafta
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not p
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %15adobe · flash player23 Oca 2015
- CVE-2018-100060062Bu hafta
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java t
YüksekCVSS 8,8Kavram kanıtıEPSS %91jenkins · github26 Haz 2018
- CVE-2018-012762Bu hafta
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allo
KritikCVSS 9,8Kavram kanıtıEPSS %77cisco · rv132w firmware8 Şub 2018
- CVE-2025-6868662Bu hafta
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,
OrtaCVSS 5,9KEVSilahlaştırılmışEPSS %30fortinet · fortios10 Şub 2026
- CVE-2025-1174961Bu hafta
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
KritikCVSS 9,8SilahlaştırılmışEPSS %75tigroumeow · ai engine – the chatbot, ai framework & mcp for wordpress5 Kas 2025
- CVE-2018-725161Bu hafta
An issue was discovered in config/error.php in Anchor 0.12.3.
KritikCVSS 9,8Kavram kanıtıEPSS %72anchorcms · anchor19 Şub 2018
- CVE-2022-2082159Planlayın
Cisco IOS XR Software Health Check Open Port Vulnerability
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %11cisco · ios xr26 May 2022
- CVE-2016-218358Planlayın
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
YüksekCVSS 7,5Kavram kanıtıEPSS %95redhat · jboss enterprise application platform31 Ağu 2016
- CVE-2016-1017558Planlayın
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI.
KritikCVSS 9,8SilahlaştırılmışEPSS %65netgear · wnr2000v5 firmware30 Oca 2017
- CVE-2017-1116558Planlayın
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for th
KritikCVSS 9,8Kavram kanıtıEPSS %64thermofisher · dt80 dex firmware12 Tem 2017
- CVE-2011-349757Planlayın
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possib
KritikCVSS 10,0SilahlaştırılmışEPSS %57measuresoft · scadapro16 Eyl 2011
- CVE-2017-1689456Planlayın
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct re
YüksekCVSS 7,5SilahlaştırılmışEPSS %87laravel · laravel19 Kas 2017
- CVE-2018-499356Planlayın
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO ha
YüksekCVSS 7,5SilahlaştırılmışEPSS %87adobe · acrobat dc9 Tem 2018