Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2022-04-27 CVE-2022-22277 Information Exposure vulnerability in Sonicwall products
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
network
low complexity
sonicwall CWE-200
5.3
2022-04-26 CVE-2022-24866 Information Exposure vulnerability in Discourse Assign
Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform.
network
low complexity
discourse CWE-200
4.3
2022-04-14 CVE-2022-24853 Information Exposure vulnerability in Metabase
Metabase is an open source business intelligence and analytics application.
network
high complexity
metabase CWE-200
5.3
2022-04-14 CVE-2022-25166 Information Exposure vulnerability in Amazon AWS Client VPN 2.0.0
An issue was discovered in Amazon AWS VPN Client 2.0.0.
local
low complexity
amazon CWE-200
5.0
2022-04-14 CVE-2021-43287 Information Exposure vulnerability in Thoughtworks Gocd
An issue was discovered in ThoughtWorks GoCD before 21.3.0.
network
low complexity
thoughtworks CWE-200
7.5
2022-04-13 CVE-2022-22961 Information Exposure vulnerability in VMWare products
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information.
network
low complexity
vmware CWE-200
5.3
2022-04-12 CVE-2022-27241 Information Exposure vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.11), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12).
network
low complexity
mendix CWE-200
7.5
2022-04-06 CVE-2021-43205 Information Exposure vulnerability in Fortinet Forticlient
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external binaries.
network
low complexity
fortinet CWE-200
5.3
2022-04-06 CVE-2021-40375 Information Exposure vulnerability in Apperta Openeyes 3.5.1
Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege.
network
low complexity
apperta CWE-200
6.5
2022-04-01 CVE-2019-14839 Information Exposure vulnerability in Redhat products
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
network
low complexity
redhat CWE-200
7.5