Total
18 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-32488 | 1 Dell | 1 Powerscale Onefs | 2026-02-20 | N/A | 5.3 MEDIUM |
|
Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.
|
|||||
| CVE-2025-13084 | 2025-12-01 | N/A | 7.6 HIGH | ||
|
The users endpoint in the groov View API returns a list of all users and
associated metadata including their API keys. This endpoint requires an
Editor role to access and will display API keys for all users,
including Administrators.
|
|||||
| CVE-2023-50458 | 1 Dradisframework | 1 Dradis | 2025-11-07 | N/A | 3.5 LOW |
|
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
|
|||||
| CVE-2024-47517 | 1 Arista | 1 Ng Firewall | 2025-09-29 | N/A | 6.8 MEDIUM |
|
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
|
|||||
| CVE-2025-30038 | 2025-08-29 | N/A | N/A | ||
|
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.
|
|||||
| CVE-2025-47324 | 1 Qualcomm | 2 Qca7005, Qca7005 Firmware | 2025-08-18 | N/A | 7.5 HIGH |
|
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
|
|||||
| CVE-2025-8713 | 2025-08-15 | N/A | 3.1 LOW | ||
|
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in pa ...
Show More |
|||||
| CVE-2025-26527 | 1 Moodle | 1 Moodle | 2025-08-08 | N/A | 5.3 MEDIUM |
|
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
|
|||||
| CVE-2025-0330 | 1 Litellm | 1 Litellm | 2025-08-01 | N/A | 7.5 HIGH |
|
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing all requests.
|
|||||
| CVE-2024-9447 | 1 Superagi | 1 Superagi | 2025-07-29 | N/A | 6.5 MEDIUM |
|
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any organization. This could lead to unauthorized access to services and significant data breaches or financial loss.
|
|||||
| CVE-2025-48941 | 1 Mybb | 1 Mybb | 2025-07-02 | N/A | 5.3 MEDIUM |
|
MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden (draft, unapproved, or soft-deleted) threads containing specified text in the title. The visibility state (`mybb_threads.visible` integer column) of threads is not validated in internal search queries, whose result is used to output a general success or failure of the search. While MyBB validates permission ...
Show More |
|||||
| CVE-2024-9099 | 1 Lunary | 1 Lunary | 2025-04-10 | N/A | 8.1 HIGH |
|
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized users to retrieve sensitive credentials, which can be used to perform actions on behalf of the project, access private data, and delete resources. The private API keys are exposed in the developer tools when the endpoint is called from the frontend.
|
|||||
| CVE-2025-1921 | 1 Google | 1 Chrome | 2025-04-01 | N/A | 6.5 MEDIUM |
|
Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium)
|
|||||
| CVE-2024-10324 | 1 Rometheme | 1 Romethemekit For Elementor | 2025-02-04 | N/A | 4.3 MEDIUM |
|
The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the register_controls function in widgets/offcanvas-rometheme.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
|
|||||
| CVE-2024-53291 | 1 Dell | 1 Nativeedge Orchestrator | 2025-01-29 | N/A | 7.5 HIGH |
|
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
|
|||||
| CVE-2023-1974 | 1 Answer | 1 Answer | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
|
|||||
| CVE-2024-49395 | 3 Mutt, Neomutt, Redhat | 3 Mutt, Neomutt, Enterprise Linux | 2024-11-14 | N/A | 5.3 MEDIUM |
|
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
|
|||||
| CVE-2024-8910 | 1 Hasthemes | 1 Ht Mega | 2024-10-03 | N/A | 4.3 MEDIUM |
|
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
|
|||||