CVE-2025-24556 – WordPress MooWoodle plugin <= 3.2.4 - Sensitive Data Exposure vulnerability
https://notcve.org/view.php?id=CVE-2025-24556
03 Feb 2025 — Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle allows Retrieve Embedded Sensitive Data. • https://patchstack.com/database/wordpress/plugin/moowoodle/vulnerability/wordpress-moowoodle-plugin-3-2-4-sensitive-data-exposure-vulnerability? • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2025-20643
https://notcve.org/view.php?id=CVE-2025-20643
03 Feb 2025 — This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. • https://corp.mediatek.com/product-security-bulletin/February-2025 • CWE-1295: Debug Messages Revealing Unnecessary Information •
CVE-2025-20640
https://notcve.org/view.php?id=CVE-2025-20640
03 Feb 2025 — This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/February-2025 • CWE-125: Out-of-bounds Read •
CVE-2025-20638
https://notcve.org/view.php?id=CVE-2025-20638
03 Feb 2025 — In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/February-2025 • CWE-457: Use of Uninitialized Variable •
CVE-2024-45089 – IBM Sterling B2B Integrator information disclosure
https://notcve.org/view.php?id=CVE-2024-45089
31 Jan 2025 — IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an observable discrepancy. • https://www.ibm.com/support/pages/node/7182063 • CWE-203: Observable Discrepancy •
CVE-2025-24597 – WordPress Barcode Generator for WooCommerce plugin <= 2.0.2 - Sensitive Data Exposure vulnerability
https://notcve.org/view.php?id=CVE-2025-24597
31 Jan 2025 — Insertion of Sensitive Information Into Sent Data vulnerability in UkrSolution Barcode Generator for WooCommerce allows Retrieve Embedded Sensitive Data. • https://patchstack.com/database/wordpress/plugin/embedding-barcodes-into-product-pages-and-orders/vulnerability/wordpress-barcode-generator-for-woocommerce-plugin-2-0-2-sensitive-data-exposure-vulnerability? • CWE-201: Insertion of Sensitive Information Into Sent Data •
CVE-2025-0902 – PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-0902
31 Jan 2025 — The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. •
CVE-2025-0904 – PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-0904
31 Jan 2025 — The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. •
CVE-2025-0905 – PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-0905
31 Jan 2025 — The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. •
CVE-2025-0906 – PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-0906
31 Jan 2025 — The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. •