Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2018-20939 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
local
low complexity
cpanel CWE-200
3.3
2019-08-01 CVE-2016-10844 Information Exposure vulnerability in Cpanel
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
network
low complexity
cpanel CWE-200
6.5
2019-08-01 CVE-2018-20913 Information Exposure vulnerability in Cpanel
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
network
low complexity
cpanel CWE-200
4.9
2019-08-01 CVE-2018-20902 Information Exposure vulnerability in Cpanel
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
local
low complexity
cpanel CWE-200
5.5
2019-08-01 CVE-2018-20894 Information Exposure vulnerability in Cpanel
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
local
low complexity
cpanel CWE-200
3.3
2019-08-01 CVE-2018-20889 Information Exposure vulnerability in Cpanel
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
local
low complexity
cpanel CWE-200
4.4
2019-07-30 CVE-2018-20870 Information Exposure vulnerability in Cpanel
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
local
low complexity
cpanel CWE-200
5.5
2019-07-29 CVE-2018-17211 Information Exposure vulnerability in Printeron Central Print Services 2.5/4.1.4
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4.
network
low complexity
printeron CWE-200
5.3
2019-07-29 CVE-2015-9288 Information Exposure vulnerability in Unity web Player
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
network
low complexity
unity CWE-200
6.5
2019-07-26 CVE-2019-14280 Information Exposure vulnerability in Craftcms Craft CMS
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
network
low complexity
craftcms CWE-200
5.3