Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2020-05-27 CVE-2020-4226 Information Exposure vulnerability in IBM Mobilefirst Platform Foundation 8.0.0.0
IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters.
network
low complexity
ibm CWE-200
7.5
2020-05-26 CVE-2020-6830 Information Exposure vulnerability in Mozilla Firefox
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions.
network
low complexity
mozilla CWE-200
7.5
2020-05-21 CVE-2020-6489 Information Exposure vulnerability in multiple products
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
network
low complexity
google debian opensuse fedoraproject CWE-200
4.3
2020-05-20 CVE-2020-5364 Information Exposure vulnerability in Dell EMC Isilon Onefs
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain an SNMPv2 vulnerability.
network
low complexity
dell CWE-200
7.5
2020-05-18 CVE-2020-13129 Information Exposure vulnerability in Heinekingmedia Stashcat
An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms.
network
low complexity
heinekingmedia CWE-200
7.2
2020-05-14 CVE-2020-0092 Information Exposure vulnerability in Google Android 10.0
In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification content due to a permissions bypass.
local
low complexity
google CWE-200
5.0
2020-05-12 CVE-2020-12772 Information Exposure vulnerability in Igniterealtime Spark 2.8.3
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows.
network
low complexity
igniterealtime CWE-200
8.8
2020-05-07 CVE-2015-7946 Information Exposure vulnerability in Ubports Unity8
Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere.
low complexity
ubports CWE-200
4.6
2020-05-07 CVE-2019-18867 Information Exposure vulnerability in Blaauwproducts Remote Kiln Control 3.0.0
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code.
network
low complexity
blaauwproducts CWE-200
7.5
2020-05-05 CVE-2020-11033 Information Exposure vulnerability in multiple products
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User.
network
low complexity
glpi-project fedoraproject CWE-200
7.2