Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2022-05-26 CVE-2022-24414 Information Exposure vulnerability in Dell Cloudlink
Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests.
network
low complexity
dell CWE-200
6.5
2022-05-24 CVE-2022-29567 Information Exposure vulnerability in Vaadin
The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.
network
low complexity
vaadin CWE-200
7.5
2022-05-17 CVE-2020-4957 Information Exposure vulnerability in IBM Security Identity Governance and Intelligence 5.2.6
IBM Security Identity Governance and Intelligence 5.2.6 could disclose sensitive information in URL parameters that could aid in future attacks against the system.
network
low complexity
ibm CWE-200
5.3
2022-05-07 CVE-2022-30334 Information Exposure vulnerability in Brave
Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers.
network
low complexity
brave CWE-200
5.3
2022-05-05 CVE-2022-25990 Information Exposure vulnerability in F5 F5Os-A 1.0.0
On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally.
network
low complexity
f5 CWE-200
5.3
2022-05-05 CVE-2022-27875 Information Exposure vulnerability in F5 Access for Android
On F5 Access for Android 3.x versions prior to 3.0.8, a Task Hijacking vulnerability exists in the F5 Access for Android application, which may allow an attacker to steal sensitive user information.
local
low complexity
f5 CWE-200
5.5
2022-05-05 CVE-2021-39020 Information Exposure vulnerability in IBM Guardium Data Encryption
IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters.
network
low complexity
ibm CWE-200
5.3
2022-05-04 CVE-2022-20734 Information Exposure vulnerability in Cisco Catalyst Sd-Wan Manager
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive information on an affected system.
local
low complexity
cisco CWE-200
4.4
2022-05-04 CVE-2022-25787 Information Exposure vulnerability in Secomea products
Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection.
local
low complexity
secomea CWE-200
6.7
2022-04-27 CVE-2022-22276 Information Exposure vulnerability in Sonicwall products
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
network
low complexity
sonicwall CWE-200
5.3