Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-10-17 CVE-2019-13410 Information Exposure vulnerability in Topmeeting
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page.
network
low complexity
topmeeting CWE-200
7.5
2019-10-17 CVE-2019-17671 Information Exposure vulnerability in multiple products
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
network
low complexity
wordpress debian CWE-200
5.3
2019-10-16 CVE-2019-12708 Information Exposure vulnerability in Cisco Spa112 Firmware and Spa122 Firmware
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to access sensitive information on an affected device.
network
low complexity
cisco CWE-200
6.5
2019-10-11 CVE-2019-2183 Information Exposure vulnerability in Google Android 10.0/9.0
In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching optimization.
local
low complexity
google CWE-200
5.5
2019-10-11 CVE-2015-9492 Information Exposure vulnerability in Smartit Premium Responsive Project Smartit Premium Responsive 20150515
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9491 Information Exposure vulnerability in Blessing Premium Responsive Project Blessing Premium Responsive 20150515
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9490 Information Exposure vulnerability in Gamestheme Premium Project Gamestheme Premium 20150515
The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
network
low complexity
gamestheme-premium-project CWE-200
7.5
2019-10-11 CVE-2015-9489 Information Exposure vulnerability in Goodnex Premium Responsive Project Goodnex Premium Responsive 20150515
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9488 Information Exposure vulnerability in Almera Responsive Portfolio Site Template Project Almera Responsive Portfolio Site Template 20150515
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9487 Information Exposure vulnerability in Almera Responsive Portfolio Project Almera Responsive Portfolio 20150515
The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5