Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10786 1 Cpanel 1 Cpanel 2019-08-09 4.0 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
CVE-2019-1009 1 Microsoft 2 Windows 7, Windows Server 2008 2019-08-09 4.3 MEDIUM 6.5 MEDIUM
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1010, CVE-2019-1011, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1016, CVE-2019-1046, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050.
CVE-2016-10811 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
CVE-2016-10810 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
CVE-2016-10809 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
CVE-2018-20942 1 Cpanel 1 Cpanel 2019-08-09 1.9 LOW 2.5 LOW
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
CVE-2017-18436 1 Cpanel 1 Cpanel 2019-08-09 2.7 LOW 3.5 LOW
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
CVE-2016-10785 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
CVE-2018-20952 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
CVE-2018-20941 1 Cpanel 1 Cpanel 2019-08-08 4.7 MEDIUM 5.6 MEDIUM
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
CVE-2016-10844 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
CVE-2012-6497 1 Rubyonrails 2 Rails, Ruby On Rails 2019-08-08 5.0 MEDIUM N/A
The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known secret_token value, as demonstrated by a value contained in secret_token.rb in an open-source product.
CVE-2009-3086 1 Rubyonrails 1 Rails 2019-08-08 5.0 MEDIUM N/A
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
CVE-2018-20946 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
CVE-2018-20944 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
CVE-2018-20939 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
CVE-2018-20889 1 Cpanel 1 Cpanel 2019-08-07 3.6 LOW 4.4 MEDIUM
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
CVE-2018-20894 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
CVE-2019-7852 1 Magento 1 Magento 2019-08-06 5.0 MEDIUM 5.3 MEDIUM
A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin panel, disclosing its location to potentially unauthorized parties.
CVE-2017-15112 1 Keycloak-httpd-client-install Project 1 Keycloak-httpd-client-install 2019-08-06 2.1 LOW 7.8 HIGH
keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.