Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2011-3269
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Sca…
X950 Firmware
Mitigation only
MEDIUM 5.3
CVE-2011-4538
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
X860 Firmware
Mitigation only
MEDIUM 6.5
CVE-2016-1159
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry…
Manageengine Password Manager Pro
Mitigation only
MEDIUM 6.5
CVE-2020-9282
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network respo…
Mahara
18.10.5 / 19.04.4+
HIGH 7.5
CVE-2020-10096
An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either rem…
Zammad
after 3.2.0
HIGH 7.5
CVE-2020-7130
HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of…
Oneview Global Dashboard
Mitigation only
MEDIUM 5.3
CVE-2020-3193
A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to ob…
Prime Collaboration Provisioning
12.6+
CRITICAL 9.8
CVE-2019-14893
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of ma…
Jackson Databind
2.8.11.5 / 2.9.10+
CRITICAL 9.8
CVE-2019-14892EPSS 6%
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…
Decision Manager
2.6.7.3 / 2.8.11.5+
MEDIUM 5.3
CVE-2018-8877
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows rem…
Asus Firmware
3.0.0.4.382.50470 / 384.4+
MEDIUM 5.3
CVE-2018-8878
Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows rem…
Asuswrt Merlin
3.0.0.4.382.50470 / 384.4+
MEDIUM 6.5
CVE-2020-9337
In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.
Course Manager
Mitigation only
HIGH 7.5
CVE-2020-5244
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. Th…
Buddypress
5.1.2+
MEDIUM 5.5
CVE-2012-0844
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.
Debian Linux
after 2.8
MEDIUM 5.9
CVE-2013-3587EPSS 6%
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted d…
Big Ip Access Policy Manager
after 12.1.2
MEDIUM 6.5
CVE-2013-3551
Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS IT…
Otrs
3.0.8 / 3.0.20+
MEDIUM 6.5
CVE-2013-4088
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not p…
Otrs
3.0.21 / 3.1.17+
MEDIUM 5.5
CVE-2011-4915
fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
Linux Kernel
after 3.1
HIGH 7.5
CVE-2014-4019EPSS 13%
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows…
Zxv10 W300 Firmware
No fix yet
MEDIUM 5.5
CVE-2014-4658
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai…
Ansible
1.5.5+
HIGH 8.8
CVE-2020-9043EPSS 8%
The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
Wpcentral
1.5.1+
HIGH 7.5
CVE-2019-6193
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated…
Xclarity Administrator
2.6.6+
HIGH 7.5
CVE-2013-5687
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
Risknet Acquirer
No fix yet
HIGH 7.5
CVE-2012-6091
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
Magento
1.7.0.2+
MEDIUM 5.5
CVE-2018-3987
An exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats…
Viber
No fix yet
MEDIUM 5.8
CVE-2020-6190
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about th…
Netweaver Application Server Java
Mitigation only
HIGH 7.5
CVE-2011-3901
Android SQLite Journal before 4.0.1 has an information disclosure vulnerability.
Android
No fix yet
MEDIUM 5.9
CVE-2013-6681
Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability
Tube Map
3.0.22+
MEDIUM 6.5
CVE-2017-18642
Syska Smart Bulb devices through 2017-08-06 receive RGB parameters over cleartext Bluetooth Low Energy (BLE), leading to sniffing, reverse engineerin…
Smartlight Rainbow Led Smart Bulb Firmware
after 2017-08-06
MEDIUM 5.7
CVE-2012-1994
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
Systems Insight Manager
7.0+