Show filters
331 Total Results
Displaying 291-300 of 331
Sort by:
Attacker Value
Unknown

CVE-2020-14337

Disclosure Date: July 31, 2020 (last updated February 21, 2025)
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2020-8213

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP response code and response timing.
Attacker Value
Unknown

CVE-2020-15125

Disclosure Date: July 29, 2020 (last updated February 21, 2025)
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management API
Attacker Value
Unknown

CVE-2020-13997

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.
Attacker Value
Unknown

CVE-2020-4572

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184179.
Attacker Value
Unknown

CVE-2020-4319

Disclosure Date: July 27, 2020 (last updated February 21, 2025)
IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.
Attacker Value
Unknown

CVE-2020-6511

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Attacker Value
Unknown

CVE-2020-15478

Disclosure Date: July 01, 2020 (last updated February 21, 2025)
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
Attacker Value
Unknown

CVE-2020-4341

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178181.
Attacker Value
Unknown

CVE-2020-4327

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 177599.