Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-21733 1 Zte 1 Zxcdn 2021-05-28 4.0 MEDIUM 4.9 MEDIUM
The management system of ZXCDN is impacted by the information leak vulnerability. Attackers can make further analysis according to the information returned by the program, and then obtain some sensitive information. This affects ZXCDN V7.01 all versions up to IAMV7.01.01.02.
CVE-2021-32624 1 Keystonejs 1 Keystone-5 2021-05-28 3.5 LOW 5.3 MEDIUM
Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly discovered capability in our query infrastructure to directly or indirectly expose the values of private fields, bypassing the configured access control. This is an access control related oracle attack in that the attack method guides an attacker during their attempt to reveal information they do not have access to. The complexity of completing the attack is limited by some length-dependent behaviors and the fidelity of the exposed information. Under some circumstances, field values or field value meta data can be determined, despite the field or list having `read` access control configured. If you use private fields or lists, you may be impacted. No patches exist at this time. There are no workarounds at this time
CVE-2020-23768 1 Phpyun 1 Phpyun 2021-05-27 5.0 MEDIUM 7.5 HIGH
An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interface on PHPPYUN prior to version 5.0.1. If exploited, this vulnerability will allow attackers to obtain users' personally identifiable information including e-mail address and telephone numbers.
CVE-2021-29681 3 Ibm, Linux, Microsoft 4 Aix, Infosphere Information Server, Linux Kernel and 1 more 2021-05-26 5.0 MEDIUM 5.3 MEDIUM
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918.
CVE-2021-20529 1 Ibm 1 Control Center 2021-05-25 5.0 MEDIUM 5.3 MEDIUM
IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 198763.
CVE-2021-29043 1 Liferay 2 Dxp, Liferay Portal 2021-05-24 4.3 MEDIUM 5.9 MEDIUM
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.
CVE-2011-3441 1 Apple 1 Iphone Os 2021-05-22 4.3 MEDIUM N/A
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.
CVE-2020-4985 1 Ibm 1 Planning Analytics Local 2021-05-20 5.0 MEDIUM 7.5 HIGH
IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642.
CVE-2021-20993 1 Wago 10 0852-0303, 0852-0303 Firmware, 0852-1305 and 7 more 2021-05-20 5.0 MEDIUM 5.3 MEDIUM
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.
CVE-2021-20564 1 Ibm 1 Cloud Pak For Security 2021-05-20 4.3 MEDIUM 5.9 MEDIUM
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 199235.
CVE-2021-31174 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2021-05-18 2.1 LOW 5.5 MEDIUM
Microsoft Excel Information Disclosure Vulnerability
CVE-2021-31173 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2021-05-18 4.0 MEDIUM 6.5 MEDIUM
Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2021-31171 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2021-05-17 2.1 LOW 4.4 MEDIUM
Microsoft SharePoint Information Disclosure Vulnerability
CVE-2021-31184 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-05-17 2.1 LOW 5.5 MEDIUM
Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
CVE-2021-31186 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2021-05-17 4.3 MEDIUM 6.5 MEDIUM
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-31191 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2021-05-17 2.1 LOW 5.5 MEDIUM
Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
CVE-2021-31178 1 Microsoft 6 365 Apps, Excel, Office and 3 more 2021-05-17 4.3 MEDIUM 5.5 MEDIUM
Microsoft Office Information Disclosure Vulnerability
CVE-2021-31905 1 Jetbrains 1 Youtrack 2021-05-14 5.0 MEDIUM 7.5 HIGH
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
CVE-2015-0997 2 Aveva, Schneider-electric 2 Aveva Edge, Wonderware Intouch 2014 2021-05-14 5.0 MEDIUM N/A
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.
CVE-2015-0998 2 Aveva, Schneider-electric 2 Aveva Edge, Wonderware Intouch 2014 2021-05-14 3.3 LOW N/A
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.