Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2012-1161 Information Exposure vulnerability in multiple products
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
network
low complexity
moodle fedoraproject CWE-200
4.3
2019-11-14 CVE-2012-1159 Information Exposure vulnerability in multiple products
Moodle before 2.2.2: Overview report allows users to see hidden courses
network
low complexity
moodle fedoraproject CWE-200
4.3
2019-11-14 CVE-2012-1158 Information Exposure vulnerability in multiple products
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
network
low complexity
moodle fedoraproject CWE-200
4.3
2019-11-14 CVE-2012-1155 Information Exposure vulnerability in multiple products
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
network
low complexity
moodle fedoraproject redhat debian CWE-200
7.5
2019-11-13 CVE-2019-0390 Information Exposure vulnerability in SAP Diagnostics Agent 7.2
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap CWE-200
4.3
2019-11-13 CVE-2011-4972 Information Exposure vulnerability in Ckeditor 7.X1.4
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
network
low complexity
ckeditor CWE-200
7.5
2019-11-12 CVE-2019-14367 Information Exposure vulnerability in Slack-Chat Project Slack-Chat 1.5.5
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code.
network
low complexity
slack-chat-project CWE-200
7.5
2019-11-12 CVE-2019-14366 Information Exposure vulnerability in Slack WP Slacksync
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code.
network
low complexity
slack CWE-200
7.5
2019-11-12 CVE-2019-14365 Information Exposure vulnerability in Intercom 1.2.1
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code.
network
low complexity
intercom CWE-200
7.5
2019-11-12 CVE-2019-1446 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5