Security Risk Category

Information Disclosure Security Risks — Page 2

Published vulnerability pages connected to Information Disclosure. Each page keeps one canonical URL and focused remediation guidance.

320 published Information Disclosure risks

Information Disclosure risks

Showing 37–72 of 320 published risks.

highEPSS 0.004

LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including questions belonging to paid courses the attacker is not enrolled in.

CVE-2026-13765wordpressauthorization-bypassinformation-disclosure

Updated Jul 19, 2026

lowEPSS 0.002

CVE-2026-35140 dfxanalytics vulnerability

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.

CVE-2026-35140information-disclosure

Updated Jul 18, 2026

lowEPSS 0.002

CVE-2026-35142 dfxanalytics vulnerability

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.

CVE-2026-35142information-disclosure

Updated Jul 18, 2026

lowEPSS 0.001

CVE-2026-35143 dfxanalytics vulnerability

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented.

CVE-2026-35143information-disclosurecsrf

Updated Jul 18, 2026

lowEPSS 0.002

CVE-2026-35145 dfxanalytics vulnerability

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.

CVE-2026-35145web-applicationinformation-disclosure

Updated Jul 18, 2026

mediumEPSS 0.002

CVE-2026-56456 dfxanalytics vulnerability

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation.

CVE-2026-56456information-disclosure

Updated Jul 18, 2026

medium

CVE-2026-33842 windows 10 1607 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-33842windowsinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-34328 windows 10 1809 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

CVE-2026-34328windowsinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-34346 windows 10 1607 vulnerability

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CVE-2026-34346windowsinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-34349 windows 10 1809 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVE-2026-34349windowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-41087 windows 10 1607 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-41087windowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.006

CVE-2026-47282 visual studio code vulnerability

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVE-2026-47282microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-49794 windows 10 1607 vulnerability

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-49794windowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-49807 windows 10 1809 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.

CVE-2026-49807windowsmicrosoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-50300 windows 10 1607 vulnerability

Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50300linuxwindowsinput-validationinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-50316 windows 10 21h2 vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50316linuxwindowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-50350 windows 10 21h2 vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

CVE-2026-50350windowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.003

CVE-2026-54988 365 apps vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-54988microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-56193 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56193microsoftinformation-disclosure

Updated Jul 17, 2026

medium

CVE-2026-49177 windows 10 1607 vulnerability

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.

CVE-2026-49177windowsinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-50665 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-50665microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50670 windows 10 1809 vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50670linuxwindowsinput-validationinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55023 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55023microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55027 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55027microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55028 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55028microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55035 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55035microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55044 365 apps vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55044microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.003

CVE-2026-55045 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-55045microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55046 365 apps vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55046microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.005

CVE-2026-55047 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55047microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55050 365 apps vulnerability

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-55050microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-55139 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55139microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-56192 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56192microsoftinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.004

CVE-2026-56195 365 apps vulnerability

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56195microsoftinformation-disclosure

Updated Jul 17, 2026

highEPSS 0.008

CVE-2026-57102 visual studio code vulnerability

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-57102microsoftsupply-chaininformation-disclosure

Updated Jul 17, 2026

highEPSS 0.009

CVE-2026-58529 windows 11 26h1 vulnerability

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVE-2026-58529windowsinformation-disclosure

Updated Jul 17, 2026