Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-08-14 CVE-2019-1202 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects.
local
low complexity
microsoft CWE-200
4.4
2019-08-14 CVE-2019-0338 Information Exposure vulnerability in SAP Gateway
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.
network
low complexity
sap CWE-200
5.3
2019-08-13 CVE-2019-13419 Information Exposure vulnerability in Search-Guard Search Guard
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
network
low complexity
search-guard CWE-200
7.5
2019-08-12 CVE-2019-13417 Information Exposure vulnerability in Search-Guard Search Guard
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
network
low complexity
search-guard CWE-200
5.3
2019-08-07 CVE-2018-20958 Information Exposure vulnerability in Tapplock Firmware
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device.
low complexity
tapplock CWE-200
6.5
2019-08-07 CVE-2016-10811 Information Exposure vulnerability in Cpanel
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
network
low complexity
cpanel CWE-200
8.8
2019-08-07 CVE-2016-10810 Information Exposure vulnerability in Cpanel
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
network
low complexity
cpanel CWE-200
8.8
2019-08-07 CVE-2016-10809 Information Exposure vulnerability in Cpanel
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
network
low complexity
cpanel CWE-200
8.8
2019-08-06 CVE-2016-10797 Information Exposure vulnerability in Cpanel
cPanel before 58.0.4 allows WHM "Purchase and Install an SSL Certificate" page visitors to list all server domains (SEC-133).
network
low complexity
cpanel CWE-200
4.3
2019-08-06 CVE-2016-10794 Information Exposure vulnerability in Cpanel
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
network
low complexity
cpanel CWE-200
6.5