Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2021-06-28 CVE-2021-32720 Information Exposure vulnerability in Sylius
Sylius is an Open Source eCommerce platform on top of Symfony.
network
low complexity
sylius CWE-200
5.3
2021-06-23 CVE-2021-29086 Information Exposure vulnerability in Synology products
Exposure of sensitive information to an unauthorized actor vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
synology CWE-200
7.5
2021-06-11 CVE-2020-12987 Information Exposure vulnerability in AMD Radeon PRO Software and Radeon Software
A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
local
low complexity
amd CWE-200
5.5
2021-06-11 CVE-2021-22905 Information Exposure vulnerability in Nextcloud
Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for sharees being performed by default on the lookup server instead of only using the local Nextcloud server unless a global search has been explicitly chosen by the user.
network
low complexity
nextcloud CWE-200
6.5
2021-06-11 CVE-2021-22912 Information Exposure vulnerability in Nextcloud
Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user.
network
low complexity
nextcloud CWE-200
6.5
2021-06-11 CVE-2021-22913 Information Exposure vulnerability in Nextcloud Deck
Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Nextcloud server unless a global search has been explicitly chosen by the user.
network
low complexity
nextcloud CWE-200
6.5
2021-06-11 CVE-2021-28805 Information Exposure vulnerability in Qnap QSS 1.0.2/1.0.3
Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS.
local
low complexity
qnap CWE-200
5.5
2021-06-04 CVE-2021-33839 Information Exposure vulnerability in Luca-App Luca
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.
network
low complexity
luca-app CWE-200
7.5
2021-06-02 CVE-2017-8761 Information Exposure vulnerability in Openstack Swift
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs.
network
low complexity
openstack CWE-200
4.3
2021-06-01 CVE-2021-20585 Information Exposure vulnerability in IBM Security Verify Access 20.07
IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system.
network
low complexity
ibm CWE-200
5.3