Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-21733 | 1 Zte | 1 Zxcdn | 2021-05-28 | 4.0 MEDIUM | 4.9 MEDIUM |
The management system of ZXCDN is impacted by the information leak vulnerability. Attackers can make further analysis according to the information returned by the program, and then obtain some sensitive information. This affects ZXCDN V7.01 all versions up to IAMV7.01.01.02. | |||||
CVE-2021-32624 | 1 Keystonejs | 1 Keystone-5 | 2021-05-28 | 3.5 LOW | 5.3 MEDIUM |
Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly discovered capability in our query infrastructure to directly or indirectly expose the values of private fields, bypassing the configured access control. This is an access control related oracle attack in that the attack method guides an attacker during their attempt to reveal information they do not have access to. The complexity of completing the attack is limited by some length-dependent behaviors and the fidelity of the exposed information. Under some circumstances, field values or field value meta data can be determined, despite the field or list having `read` access control configured. If you use private fields or lists, you may be impacted. No patches exist at this time. There are no workarounds at this time | |||||
CVE-2020-23768 | 1 Phpyun | 1 Phpyun | 2021-05-27 | 5.0 MEDIUM | 7.5 HIGH |
An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interface on PHPPYUN prior to version 5.0.1. If exploited, this vulnerability will allow attackers to obtain users' personally identifiable information including e-mail address and telephone numbers. | |||||
CVE-2021-29681 | 3 Ibm, Linux, Microsoft | 4 Aix, Infosphere Information Server, Linux Kernel and 1 more | 2021-05-26 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918. | |||||
CVE-2021-20529 | 1 Ibm | 1 Control Center | 2021-05-25 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 198763. | |||||
CVE-2021-29043 | 1 Liferay | 2 Dxp, Liferay Portal | 2021-05-24 | 4.3 MEDIUM | 5.9 MEDIUM |
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing. | |||||
CVE-2011-3441 | 1 Apple | 1 Iphone Os | 2021-05-22 | 4.3 MEDIUM | N/A |
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname. | |||||
CVE-2020-4985 | 1 Ibm | 1 Planning Analytics Local | 2021-05-20 | 5.0 MEDIUM | 7.5 HIGH |
IBM Planning Analytics Local 2.0 could allow an attacker to obtain sensitive information due to accepting body parameters in a query. IBM X-Force ID: 192642. | |||||
CVE-2021-20993 | 1 Wago | 10 0852-0303, 0852-0303 Firmware, 0852-1305 and 7 more | 2021-05-20 | 5.0 MEDIUM | 5.3 MEDIUM |
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory. | |||||
CVE-2021-20564 | 1 Ibm | 1 Cloud Pak For Security | 2021-05-20 | 4.3 MEDIUM | 5.9 MEDIUM |
IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 199235. | |||||
CVE-2021-31174 | 1 Microsoft | 5 365 Apps, Excel, Office and 2 more | 2021-05-18 | 2.1 LOW | 5.5 MEDIUM |
Microsoft Excel Information Disclosure Vulnerability | |||||
CVE-2021-31173 | 1 Microsoft | 2 Sharepoint Foundation, Sharepoint Server | 2021-05-18 | 4.0 MEDIUM | 6.5 MEDIUM |
Microsoft SharePoint Server Information Disclosure Vulnerability | |||||
CVE-2021-31171 | 1 Microsoft | 2 Sharepoint Foundation, Sharepoint Server | 2021-05-17 | 2.1 LOW | 4.4 MEDIUM |
Microsoft SharePoint Information Disclosure Vulnerability | |||||
CVE-2021-31184 | 1 Microsoft | 8 Windows 10, Windows 7, Windows 8.1 and 5 more | 2021-05-17 | 2.1 LOW | 5.5 MEDIUM |
Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability | |||||
CVE-2021-31186 | 1 Microsoft | 8 Windows 10, Windows 7, Windows 8.1 and 5 more | 2021-05-17 | 4.3 MEDIUM | 6.5 MEDIUM |
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | |||||
CVE-2021-31191 | 1 Microsoft | 3 Windows 10, Windows Server 2016, Windows Server 2019 | 2021-05-17 | 2.1 LOW | 5.5 MEDIUM |
Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | |||||
CVE-2021-31178 | 1 Microsoft | 6 365 Apps, Excel, Office and 3 more | 2021-05-17 | 4.3 MEDIUM | 5.5 MEDIUM |
Microsoft Office Information Disclosure Vulnerability | |||||
CVE-2021-31905 | 1 Jetbrains | 1 Youtrack | 2021-05-14 | 5.0 MEDIUM | 7.5 HIGH |
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible. | |||||
CVE-2015-0997 | 2 Aveva, Schneider-electric | 2 Aveva Edge, Wonderware Intouch 2014 | 2021-05-14 | 5.0 MEDIUM | N/A |
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack. | |||||
CVE-2015-0998 | 2 Aveva, Schneider-electric | 2 Aveva Edge, Wonderware Intouch 2014 | 2021-05-14 | 3.3 LOW | N/A |
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network. |