Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2022-03-02 CVE-2022-23779 Information Exposure vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone.
network
low complexity
zohocorp CWE-200
5.3
2022-03-02 CVE-2022-22303 Information Exposure vulnerability in Fortinet Fortimanager
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.
local
low complexity
fortinet CWE-200
5.5
2022-02-28 CVE-2021-25118 Information Exposure vulnerability in Yoast SEO
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
network
low complexity
yoast CWE-200
5.3
2022-02-24 CVE-2022-24633 Information Exposure vulnerability in Filecloud
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.
network
low complexity
filecloud CWE-200
5.3
2022-02-21 CVE-2022-0708 Information Exposure vulnerability in Mattermost
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
network
low complexity
mattermost CWE-200
6.5
2022-02-21 CVE-2022-23984 Information Exposure vulnerability in Gvectors Wpdiscuz
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
network
low complexity
gvectors CWE-200
7.5
2022-02-18 CVE-2022-0672 Information Exposure vulnerability in Eclipse Lemminx
A flaw was found in LemMinX in versions prior to 0.19.0.
local
low complexity
eclipse CWE-200
5.5
2022-02-18 CVE-2022-23982 Information Exposure vulnerability in Quadlayers Perfect Brands for Woocommerce
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
network
low complexity
quadlayers CWE-200
7.5
2022-02-14 CVE-2021-45310 Information Exposure vulnerability in Sangoma Switchvox 102409
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction.
network
low complexity
sangoma CWE-200
5.3
2022-02-14 CVE-2021-45421 Information Exposure vulnerability in Emerson Dixell Xweb-500 Firmware
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing.
network
low complexity
emerson CWE-200
7.5