Page 8 of 10841 results (0.215 seconds)

CVSS: 4.3EPSS: 0%CPEs: -EXPL: 0

This vulnerability discloses private information and affects all versions prior to the fix. • https://github.com/janeczku/calibre-web/commit/6f5390ead5df9779ac81fadefffb476e03f93548 https://huntr.com/bounties/394af194-61a7-4e33-b373-877d4c766fca • CWE-209: Generation of Error Message Containing Sensitive Information

CVSS: 2.4EPSS: 0%CPEs: -EXPL: 0

Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext. • http://skyworth.com https://github.com/nitinronge91/Sensitive-Information-disclosure-via-SPI-flash-firmware-for-Hathway-router-CVE-2024-46383 • CWE-312: Cleartext Storage of Sensitive Information

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

This could lead to information disclosure with no additional execution privileges needed.   • https://source.android.com/security/bulletin/2018-06-01 •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance. • https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-319-01 • CWE-778: Insufficient Logging •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

An attacker with access to the Service PC where the tools are installed could obtain diagnostic information through the test tool or manipulate the ventilator's settings and embedded software via the calibration tool, without having to authenticate to either tool. This could result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance. • https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-319-01 • CWE-306: Missing Authentication for Critical Function •