CVE-2024-39182
https://notcve.org/view.php?id=CVE-2024-39182
An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root user's session via an arbitrary command (ISP6-1779). • https://ispmanager.com/changelog • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2024-37504 – WordPress FileBird Document Library plugin <= 2.0.6 - Sensitive Data Exposure vulnerability
https://notcve.org/view.php?id=CVE-2024-37504
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6. ... The FileBird Document Library plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.6 due to insufficient user access checking. • https://patchstack.com/database/vulnerability/filebird-document-library/wordpress-filebird-document-library-plugin-2-0-6-sensitive-data-exposure-vulnerability? • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2024-37498 – WordPress Tablesome plugin <= 1.0.33 - Sensitive Data Exposure via API vulnerability
https://notcve.org/view.php?id=CVE-2024-37498
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.33. ... The Tablesome – Responsive Table, Woocommerce Automation, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.33 due to insufficient capability checks on the get_export_table_props function. This makes it possible for unauthenticated attackers to extract potentially sensitive information from tables. • https://patchstack.com/database/vulnerability/tablesome/wordpress-tablesome-plugin-1-0-33-sensitive-data-exposure-via-api-vulnerability? • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2024-31223 – Fides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
https://notcve.org/view.php?id=CVE-2024-31223
This could result in disclosure of server-side configuration giving an attacker information on server-side ports, private IP addresses, and/or private domain names. • https://github.com/ethyca/fides/commit/0555080541f18a5aacff452c590ac9a1b56d7097 https://github.com/ethyca/fides/security/advisories/GHSA-53q7-4874-24qg • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere •
CVE-2024-32757 – American Dynamics Illustra Essentials Gen 4 - Linux Credential Leak
https://notcve.org/view.php?id=CVE-2024-32757
Under certain circumstances unnecessary user details are provided within system logs • https://www.cisa.gov/news-events/ics-advisories/icsa-24-179-06 https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories • CWE-532: Insertion of Sensitive Information into Log File •