Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2020-06-19 CVE-2017-18895 Information Exposure vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5.
network
low complexity
mattermost CWE-200
5.3
2020-06-19 CVE-2017-18887 Information Exposure vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2.
network
low complexity
mattermost CWE-200
5.3
2020-06-19 CVE-2018-21260 Information Exposure vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3.
network
low complexity
mattermost CWE-200
2.7
2020-06-18 CVE-2019-13033 Information Exposure vulnerability in multiple products
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed.
local
low complexity
cisofy debian fedoraproject CWE-200
3.3
2020-06-18 CVE-2020-3347 Information Exposure vulnerability in Cisco Webex Meetings 39.5.25/39.5.26/40.6.0
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system.
local
low complexity
cisco CWE-200
5.5
2020-06-18 CVE-2020-3242 Information Exposure vulnerability in Cisco UCS Director
A vulnerability in the REST API of Cisco UCS Director could allow an authenticated, remote attacker with administrative privileges to obtain confidential information from an affected device.
network
low complexity
cisco CWE-200
4.9
2020-06-17 CVE-2020-7932 Information Exposure vulnerability in Openmicroscopy Omero.Web
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters.
network
low complexity
openmicroscopy CWE-200
5.7
2020-06-16 CVE-2020-7510 Information Exposure vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2
A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtain private keys.
network
low complexity
schneider-electric CWE-200
7.5
2020-06-16 CVE-2020-7506 Information Exposure vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2
A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the archive with the firmware for the controller and modules using the usual tar archiver resulting in an information exposure.
network
low complexity
schneider-electric CWE-200
7.5
2020-06-11 CVE-2020-4045 Information Exposure vulnerability in Scuttlebutt Ssb-Db 20.0.0
SSB-DB version 20.0.0 has an information disclosure vulnerability.
network
low complexity
scuttlebutt CWE-200
7.5