Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2020-05-12 CVE-2020-1746 Information Exposure vulnerability in multiple products
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when the ldap_attr and ldap_entry community modules are used.
local
low complexity
redhat debian CWE-200
5.0
2020-05-07 CVE-2015-7946 Information Exposure vulnerability in Ubports Unity8
Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere.
low complexity
ubports CWE-200
4.6
2020-05-07 CVE-2019-18867 Information Exposure vulnerability in Blaauwproducts Remote Kiln Control 3.0.0
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code.
network
low complexity
blaauwproducts CWE-200
7.5
2020-05-05 CVE-2020-11033 Information Exposure vulnerability in multiple products
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User.
network
low complexity
glpi-project fedoraproject CWE-200
7.2
2020-05-04 CVE-2020-5331 Information Exposure vulnerability in RSA Archer
RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability.
local
low complexity
rsa CWE-200
5.5
2020-05-04 CVE-2020-10618 Information Exposure vulnerability in Lcds Laquis Scada
LCDS LAquis SCADA Versions 4.3.1 and prior.
local
low complexity
lcds CWE-200
5.5
2020-04-30 CVE-2020-6865 Information Exposure vulnerability in ZTE Oscp 16.19.10/16.19.20
ZTE SDN controller platform is impacted by an information leakage vulnerability.
network
low complexity
zte CWE-200
6.5
2020-04-30 CVE-2020-5890 Information Exposure vulnerability in F5 products
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a QKView, credentials for binding to LDAP servers used for remote authentication of the BIG-IP administrative interface will not fully obfuscate if they contain whitespace.
local
low complexity
f5 CWE-200
5.5
2020-04-30 CVE-2020-9387 Information Exposure vulnerability in Mahara
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.
network
low complexity
mahara CWE-200
4.3
2020-04-29 CVE-2020-11024 Information Exposure vulnerability in Moonlight-Stream Moonlight
In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack.
network
high complexity
moonlight-stream CWE-200
8.2