Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2019-18987
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been ma…
Abusefilter
after 1.34
HIGH 7.5
CVE-2013-3070
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK…
Wndr4700 Firmware
Patch available
MEDIUM 5.3
CVE-2012-1169
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are show…
Moodle
2.2.2+
HIGH 7.5
CVE-2012-1155
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from …
Moodle
1.9.17 / 2.0.8+
HIGH 7.5
CVE-2011-4972
hook_file_download in the CKEditor module 7.x-1.4 for Drupal does not properly restrict access to private files, which allows remote attackers to rea…
Ckeditor
Patch available
HIGH 7.5
CVE-2019-14365
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the vict…
Intercom
after 1.2.1
HIGH 7.5
CVE-2019-14366
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the vict…
Wp Slacksync
after 1.8.5
HIGH 7.5
CVE-2019-14367
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, m…
Slack Chat
after 1.5.5
MEDIUM 5.5
CVE-2019-1436
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-1439EPSS 76%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1440
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure V…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1446EPSS 8%
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information…
Excel
Patch available
MEDIUM 5.5
CVE-2019-1402
An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Micros…
Office
Patch available
MEDIUM 5.5
CVE-2019-1374EPSS 7%
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Infor…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1381
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows …
Windows 10
Patch available
MEDIUM 5.3
CVE-2019-1324
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP…
Windows 10
Patch available
MEDIUM 5.5
CVE-2019-1370
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Inf…
Open Enclave Software Development Kit
after 0.7.0
HIGH 7.5
CVE-2018-21026
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
Device Manager
8.6.5-00 / 8.7.0-00+
MEDIUM 5.3
CVE-2019-4412
IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to …
Cognos Controller
Patch available
MEDIUM 5.3
CVE-2019-13557
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access …
Tasy Emr
after 3.02.1757
MEDIUM 6.5
CVE-2008-5083
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
Jboss Operations Network
2.1.2+
HIGH 7.5
CVE-2010-2450
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed …
Debian Linux
Patch available
MEDIUM 6.2
CVE-2019-3422
The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of…
Mf910s Firmware
No fix yet
HIGH 7.5
CVE-2009-5045
Dump Servlet information leak in jetty before 6.1.22.
Debian Linux
6.1.22+
MEDIUM 6.5
CVE-2011-4900
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
TYPO3
4.5.4+
MEDIUM 6.5
CVE-2011-4901
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to extract arbitrary information from the TYPO3 database.
TYPO3
4.3.12 / 4.4.9+
MEDIUM 6.5
CVE-2011-4627
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.
TYPO3
4.3.12 / 4.4.9+
MEDIUM 5.5
CVE-2019-1734
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local…
Firepower Extensible Operating System
2.2.2.91 / 2.3.1.111+
MEDIUM 6.5
CVE-2019-1877
A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through…
Enterprise Chat And Email
No fix yet
MEDIUM 5.3
CVE-2010-3673
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
TYPO3
4.2.13 / 4.3.4+