Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-12-13 CVE-2018-13811 Information Exposure vulnerability in Siemens Simatic Step 7 (Tia Portal)
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1).
local
low complexity
siemens CWE-200
5.5
2018-12-13 CVE-2018-8033 Information Exposure vulnerability in Apache Ofbiz
In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint.
network
low complexity
apache CWE-200
7.5
2018-12-12 CVE-2018-15718 Information Exposure vulnerability in Opendental
Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user accesses the command prompt.
network
low complexity
opendental CWE-200
7.5
2018-12-12 CVE-2018-1481 Information Exposure vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters.
network
low complexity
ibm CWE-200
5.3
2018-12-12 CVE-2018-1476 Information Exposure vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
7.5
2018-12-12 CVE-2018-15328 Information Exposure vulnerability in F5 products
On BIG-IP 14.0.x, 13.x, 12.x, and 11.x, Enterprise Manager 3.1.1, BIG-IQ 6.x, 5.x, and 4.x, and iWorkflow 2.x, the passphrases for SNMPv3 users and trap destinations that are used for authentication and privacy are not handled by the BIG-IP system Secure Vault feature; they are written in the clear to the various configuration files.
network
low complexity
f5 CWE-200
7.5
2018-12-12 CVE-2018-8580 Information Exposure vulnerability in Microsoft Sharepoint Server 2010/2013/2016
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
network
low complexity
microsoft CWE-200
4.3
2018-12-11 CVE-2018-19968 Information Exposure vulnerability in multiple products
An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature.
network
low complexity
phpmyadmin debian CWE-200
6.5
2018-12-10 CVE-2018-15800 Information Exposure vulnerability in Cloud Foundry Bits Service
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability.
network
high complexity
cloud-foundry CWE-200
6.8
2018-12-10 CVE-2018-3988 Information Exposure vulnerability in Signal Private Messenger 4.24.8
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
local
high complexity
signal CWE-200
4.7