Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-02-11 CVE-2018-20776 Information Exposure vulnerability in Frog CMS Project Frog CMS 0.9.5
Frog CMS 0.9.5 provides a directory listing for a /public request.
network
low complexity
frog-cms-project CWE-200
7.5
2019-02-08 CVE-2019-7628 Information Exposure vulnerability in Redhat Pagure 5.2
Pagure 5.2 leaks API keys by e-mailing them to users.
network
high complexity
redhat CWE-200
5.9
2019-02-07 CVE-2018-1296 Information Exposure vulnerability in Apache Hadoop
In Apache Hadoop 3.0.0-alpha1 to 3.0.0, 2.9.0, 2.8.0 to 2.8.3, and 2.5.0 to 2.7.5, HDFS exposes extended attribute key/value pairs during listXAttrs, verifying only path-level search access to the directory rather than path-level read permission to the referent.
network
low complexity
apache CWE-200
7.5
2019-02-07 CVE-2019-7535 Information Exposure vulnerability in Gurock Testrail 5.3.0.3603
index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.
network
low complexity
gurock CWE-200
5.3
2019-02-06 CVE-2019-1003021 Information Exposure vulnerability in Jenkins Openid Connect Authentication
An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g.
network
low complexity
jenkins CWE-200
4.3
2019-02-06 CVE-2019-1003018 Information Exposure vulnerability in Jenkins Github Oauth
An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g.
network
low complexity
jenkins CWE-200
4.3
2019-02-05 CVE-2018-18334 Information Exposure vulnerability in Trendmicro DR. Safety
A vulnerability in the Private Browser of Trend Micro Dr.
network
low complexity
trendmicro CWE-200
7.5
2019-02-05 CVE-2017-1177 Information Exposure vulnerability in IBM Bigfix Compliance 1.7/1.8/1.9.91
IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.3
2019-02-05 CVE-2018-15659 Information Exposure vulnerability in 42Gears Suremdm 6.31/6.34
An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications.
network
low complexity
42gears CWE-200
6.5
2019-02-05 CVE-2018-15658 Information Exposure vulnerability in 42Gears Suremdm 6.31/6.34/6.35
An issue was discovered in 42Gears SureMDM before 2018-11-27.
network
low complexity
42gears CWE-200
7.5