Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2023-02-10 CVE-2022-46650 Information Exposure vulnerability in Sierrawireless Aleos
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
network
low complexity
sierrawireless CWE-200
4.9
2023-02-08 CVE-2023-25165 Information Exposure vulnerability in Helm
Helm is a tool that streamlines installing and managing Kubernetes applications.`getHostByName` is a Helm template function introduced in Helm v3.
network
low complexity
helm CWE-200
4.3
2023-02-01 CVE-2021-22786 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol.
network
low complexity
schneider-electric CWE-200
7.5
2023-01-28 CVE-2023-23628 Information Exposure vulnerability in Metabase
Metabase is an open source data analytics platform.
network
low complexity
metabase CWE-200
4.1
2023-01-28 CVE-2023-23620 Information Exposure vulnerability in Discourse
Discourse is an open-source discussion platform.
network
low complexity
discourse CWE-200
5.3
2023-01-28 CVE-2023-23624 Information Exposure vulnerability in Discourse
Discourse is an open-source discussion platform.
network
low complexity
discourse CWE-200
5.3
2023-01-26 CVE-2023-0321 Information Exposure vulnerability in Campbellsci products
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network.
network
low complexity
campbellsci CWE-200
critical
9.1
2023-01-26 CVE-2023-23613 Information Exposure vulnerability in Amazon Opensearch
OpenSearch is an open source distributed and RESTful search engine.
network
low complexity
amazon CWE-200
6.5
2023-01-20 CVE-2021-39089 Information Exposure vulnerability in IBM Cloud PAK for Security 1.10.0.0/1.10.2.0/1.10.6.0
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request.
network
low complexity
ibm CWE-200
6.5
2023-01-20 CVE-2022-39193 Information Exposure vulnerability in Mediawiki 1.39.0/1.39.1
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x.
network
low complexity
mediawiki CWE-200
5.3