Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2021-11-12 CVE-2021-30284 Information Exposure vulnerability in Qualcomm products
Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
network
low complexity
qualcomm CWE-200
critical
9.1
2021-11-05 CVE-2021-39898 Information Exposure vulnerability in Gitlab
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.
network
low complexity
gitlab CWE-200
5.3
2021-11-04 CVE-2021-34774 Information Exposure vulnerability in Cisco Common Services Platform Collector
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system.
network
low complexity
cisco CWE-200
4.9
2021-11-03 CVE-2021-36192 Information Exposure vulnerability in Fortinet Fortimanager
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.
local
low complexity
fortinet CWE-200
3.8
2021-10-15 CVE-2020-4951 Information Exposure vulnerability in multiple products
IBM Cognos Analytics 11.1.7 and 11.2.0 contains locally cached browser data, that could allow a local attacker to obtain sensitive information.
local
low complexity
ibm netapp CWE-200
3.3
2021-10-13 CVE-2021-22036 Information Exposure vulnerability in VMWare Vrealize Automation and Vrealize Orchestrator
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling.
network
low complexity
vmware CWE-200
6.5
2021-10-13 CVE-2021-20832 Information Exposure vulnerability in Inbody
InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerability which may lead to information disclosure only when it works with the body composition analyzer InBody Dial.
network
low complexity
inbody CWE-200
5.3
2021-10-07 CVE-2021-42089 Information Exposure vulnerability in Zammad
An issue was discovered in Zammad before 4.1.1.
network
low complexity
zammad CWE-200
7.5
2021-10-06 CVE-2021-0644 Information Exposure vulnerability in Google Android 10.0/11.0
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check.
local
low complexity
google CWE-200
5.5
2021-09-15 CVE-2021-40862 Information Exposure vulnerability in Hashicorp Terraform Enterprise
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configuration.
network
low complexity
hashicorp CWE-200
8.8