Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2018-10-10 CVE-2018-8292 Information Exposure vulnerability in Microsoft Asp.Net Core and Powershell Core
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
network
low complexity
microsoft CWE-200
7.5
2018-10-08 CVE-2018-1753 Information Exposure vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data.
network
low complexity
ibm CWE-200
4.3
2018-10-08 CVE-2018-1743 Information Exposure vulnerability in IBM Security KEY Lifecycle Manager
IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.3
2018-10-08 CVE-2018-1000803 Information Exposure vulnerability in Gitea
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses.
network
low complexity
gitea CWE-200
5.3
2018-10-05 CVE-2018-15433 Information Exposure vulnerability in Cisco Prime Infrastructure 3.2
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information.
network
low complexity
cisco CWE-200
4.3
2018-10-05 CVE-2018-15432 Information Exposure vulnerability in Cisco Prime Infrastructure 3.2
A vulnerability in the server backup function of Cisco Prime Infrastructure could allow an authenticated, remote attacker to view sensitive information.
network
low complexity
cisco CWE-200
4.3
2018-10-05 CVE-2018-1723 Information Exposure vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 4.1.1.0, 4.1.1.20, 4.2.0.0, 4.2.3.10, 5.0.0 and 5.0.1.2 could allow an unprivileged, authenticated user with access to a GPFS node to read arbitrary files available on this node.
local
low complexity
ibm CWE-200
5.5
2018-10-05 CVE-2014-10076 Information Exposure vulnerability in Wp-Db-Backup Project Wp-Db-Backup 2.2.4
The wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote attackers to read backup archives via a brute-force attack.
network
low complexity
wp-db-backup-project CWE-200
7.5
2018-10-04 CVE-2018-17891 Information Exposure vulnerability in Carestream VUE RIS 11.2
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5.
network
high complexity
carestream CWE-200
3.7
2018-10-04 CVE-2018-13258 Information Exposure vulnerability in Mediawiki 1.31.0
Mediawiki 1.31 before 1.31.1 misses .htaccess files in the provided tarball used to protect some directories that shouldn't be web accessible.
network
low complexity
mediawiki CWE-200
5.3