Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-10-10 CVE-2019-1334 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5
2019-10-09 CVE-2019-15859 Information Exposure vulnerability in Socomec Diris A-40 Firmware
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.
network
low complexity
socomec CWE-200
critical
9.8
2019-10-04 CVE-2019-4514 Information Exposure vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users.
network
low complexity
ibm CWE-200
5.3
2019-09-27 CVE-2019-9424 Information Exposure vulnerability in Google Android 10.0
In the Screen Lock, there is a possible information disclosure due to an unusual root cause.
network
low complexity
google CWE-200
7.5
2019-09-27 CVE-2018-9581 Information Exposure vulnerability in Google Android 10.0
In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.STATE_CHANGE intents.
local
low complexity
google CWE-200
3.3
2019-09-26 CVE-2019-15891 Information Exposure vulnerability in Cksource Ckfinder
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0.
network
low complexity
cksource CWE-200
5.3
2019-09-25 CVE-2019-14666 Information Exposure vulnerability in Glpi-Project Glpi
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature.
network
low complexity
glpi-project CWE-200
8.8
2019-09-25 CVE-2019-10407 Information Exposure vulnerability in Jenkins Project Inheritance
Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.
network
low complexity
jenkins CWE-200
6.5
2019-09-23 CVE-2018-21019 Information Exposure vulnerability in Home-Assistant
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py.
network
low complexity
home-assistant CWE-200
7.5
2019-09-20 CVE-2019-15085 Information Exposure vulnerability in Prise Adas 1.7.0
An issue was discovered in PRiSE adAS 1.7.0.
network
low complexity
prise CWE-200
7.5