Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2020-06-19 CVE-2017-18887 Information Exposure vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2.
network
low complexity
mattermost CWE-200
5.3
2020-06-19 CVE-2018-21260 Information Exposure vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3.
network
low complexity
mattermost CWE-200
2.7
2020-06-18 CVE-2019-13033 Information Exposure vulnerability in multiple products
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed.
local
low complexity
cisofy debian fedoraproject CWE-200
3.3
2020-06-18 CVE-2020-3347 Information Exposure vulnerability in Cisco Webex Meetings 39.5.25/39.5.26/40.6.0
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system.
local
low complexity
cisco CWE-200
5.5
2020-06-18 CVE-2020-3242 Information Exposure vulnerability in Cisco UCS Director
A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative privileges to obtain confidential information from an affected device.
network
low complexity
cisco CWE-200
4.9
2020-06-17 CVE-2020-7932 Information Exposure vulnerability in Openmicroscopy Omero.Web
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters.
network
low complexity
openmicroscopy CWE-200
5.7
2020-06-16 CVE-2020-7510 Information Exposure vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2
A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtain private keys.
network
low complexity
schneider-electric CWE-200
7.5
2020-06-11 CVE-2020-13702 Information Exposure vulnerability in the Rolling Proximity Identifier Project the Rolling Proximity Identifier 20200529
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID.
network
low complexity
the-rolling-proximity-identifier-project CWE-200
critical
10.0
2020-06-08 CVE-2020-1775 Information Exposure vulnerability in Otrs
BCC recipients in mails sent from OTRS are visible in article detail on external interface.
network
low complexity
otrs CWE-200
4.3
2020-06-04 CVE-2019-20836 Information Exposure vulnerability in Foxitsoftware Phantompdf
An issue was discovered in Foxit Reader and PhantomPDF before 9.5.
network
low complexity
foxitsoftware CWE-200
7.5