Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2020-04-20 CVE-2017-18847 Information Exposure vulnerability in Netgear products
Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files.
local
low complexity
netgear CWE-200
5.5
2020-04-16 CVE-2020-4338 Information Exposure vulnerability in IBM MQ
IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.
local
low complexity
ibm CWE-200
5.5
2020-04-16 CVE-2019-10523 Information Exposure vulnerability in Qualcomm products
Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCA6574AU, QCS605, Rennell, SDA660, SDM429W, SDM439, SDM450, SDM710, SDM845, SM7150, SM8150, SM8250, SXR2130
local
low complexity
qualcomm CWE-200
5.5
2020-04-15 CVE-2019-20646 Information Exposure vulnerability in Netgear Rax40 Firmware 1.0.3.62
NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of administrative credentials.
network
low complexity
netgear CWE-200
critical
9.8
2020-04-15 CVE-2019-20638 Information Exposure vulnerability in Netgear Mr1100 Firmware 12.05.05.00/12.06.03
NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials.
network
low complexity
netgear CWE-200
6.5
2020-04-15 CVE-2020-1018 Information Exposure vulnerability in Microsoft Dynamics 365 Business Central and Dynamics NAV
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.
network
low complexity
microsoft CWE-200
7.5
2020-04-14 CVE-2020-7801 Information Exposure vulnerability in Mysyngeryss Husky RTU 6049-E70 Firmware
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability.
network
low complexity
mysyngeryss CWE-200
5.3
2020-04-10 CVE-2015-9547 Information Exposure vulnerability in Google Android 4.3/4.4.2
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software.
network
low complexity
google CWE-200
7.5
2020-04-10 CVE-2020-8832 Information Exposure vulnerability in multiple products
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
local
low complexity
canonical netapp CWE-200
5.5
2020-04-09 CVE-2018-21034 Information Exposure vulnerability in Argoproj Argo CD
In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which were stored within git.
network
low complexity
argoproj CWE-200
6.5