Page 533 of 10626 results (0.041 seconds)

CVSS: 5.3EPSS: 0%CPEs: 6EXPL: 0

This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder Security Engineering team. The affected versions are before version 7.13.15, from version 7.14.0 before 7.19.7, and from version 7.20.0 before 8.2.0. • https://jira.atlassian.com/browse/CONFSERVER-82403 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure. • https://iknow.lenovo.com.cn/detail/dc_206093.html • CWE-295: Improper Certificate Validation •

CVSS: 6.5EPSS: 0%CPEs: -EXPL: 0

NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. • https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilities-on-the-RAX30-PSV-2022-0348 https://www.zerodayinitiative.com/advisories/ZDI-23-497 • CWE-306: Missing Authentication for Critical Function •

CVSS: 5.7EPSS: 0%CPEs: -EXPL: 0

NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. • https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilities-on-the-RAX30-PSV-2022-0348 https://www.zerodayinitiative.com/advisories/ZDI-23-501 • CWE-312: Cleartext Storage of Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188. • https://exchange.xforce.ibmcloud.com/vulnerabilities/253188 https://www.ibm.com/support/pages/node/6985011 https://www.ibm.com/support/pages/node/6986617 https://www.ibm.com/support/pages/node/6986637 https://www.ibm.com/support/pages/node/6987167 https://access.redhat.com/security/cve/CVE-2023-30441 https://bugzilla.redhat.com/show_bug.cgi?id=2188465 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-327: Use of a Broken or Risky Cryptographic Algorithm •