Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-200
Total 6955 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4972 1 Ckeditor 1 Ckeditor 2019-11-18 5.0 MEDIUM 7.5 HIGH
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to read private files via a direct request.
CVE-2012-1169 2 Fedoraproject, Moodle 2 Fedora, Moodle 2019-11-18 5.0 MEDIUM 5.3 MEDIUM
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
CVE-2018-21026 4 Hitachi, Linux, Microsoft and 1 more 8 Compute Systems Manager, Device Manager, Replication Manager and 5 more 2019-11-18 5.0 MEDIUM 7.5 HIGH
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
CVE-2013-3070 1 Netgear 2 Wndr4700, Wndr4700 Firmware 2019-11-18 5.0 MEDIUM 7.5 HIGH
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.
CVE-2019-0390 1 Sap 1 Diagnostics Agent 2019-11-15 4.0 MEDIUM 4.3 MEDIUM
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.
CVE-2012-1159 2 Fedoraproject, Moodle 2 Fedora, Moodle 2019-11-15 4.0 MEDIUM 4.3 MEDIUM
Moodle before 2.2.2: Overview report allows users to see hidden courses
CVE-2012-1161 2 Fedoraproject, Moodle 2 Fedora, Moodle 2019-11-15 4.0 MEDIUM 4.3 MEDIUM
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
CVE-2019-1418 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2019-11-14 2.1 LOW 3.3 LOW
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
CVE-2019-14365 1 Intercom 1 Intercom 2019-11-14 5.0 MEDIUM 7.5 HIGH
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-14366 1 Slack 1 Wp Slacksync 2019-11-14 5.0 MEDIUM 7.5 HIGH
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-14367 1 Slack-chat Project 1 Slack-chat 2019-11-14 5.0 MEDIUM 7.5 HIGH
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-1381 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2019-11-14 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.
CVE-2019-1402 1 Microsoft 2 Office, Office 365 2019-11-14 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'.
CVE-2008-5083 1 Redhat 1 Jboss Operations Network 2019-11-14 4.0 MEDIUM 6.5 MEDIUM
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
CVE-2019-1369 1 Microsoft 1 Open Enclave Software Development Kit 2019-11-13 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.
CVE-2019-1370 1 Microsoft 1 Open Enclave Software Development Kit 2019-11-13 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.
CVE-2019-1324 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2019-11-13 5.0 MEDIUM 5.3 MEDIUM
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
CVE-2019-1374 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2019-11-13 4.3 MEDIUM 5.5 MEDIUM
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'.
CVE-2019-13557 1 Philips 2 Tasy Emr, Tasy Webportal 2019-11-13 5.0 MEDIUM 5.3 MEDIUM
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information.
CVE-2010-2450 2 Debian, Shibboleth 2 Debian Linux, Service Provider 2019-11-13 5.0 MEDIUM 7.5 HIGH
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.