Security Risk Category
Information Disclosure Security Risks — Page 2
Published vulnerability pages connected to Information Disclosure. Each page keeps one canonical URL and focused remediation guidance.
320 published Information Disclosure risks
Information Disclosure risks
Showing 37–72 of 320 published risks.
LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including questions belonging to paid courses the attacker is not enrolled in.
Updated Jul 19, 2026
CVE-2026-35140 dfxanalytics vulnerability
HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.
Updated Jul 18, 2026
CVE-2026-35142 dfxanalytics vulnerability
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.
Updated Jul 18, 2026
CVE-2026-35143 dfxanalytics vulnerability
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if additional mitigations, such as Anti-CSRF tokens, are not implemented.
Updated Jul 18, 2026
CVE-2026-35145 dfxanalytics vulnerability
HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.
Updated Jul 18, 2026
CVE-2026-56456 dfxanalytics vulnerability
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which could allow a remote attacker to map the underlying server environment and identify targets for further exploitation.
Updated Jul 18, 2026
CVE-2026-33842 windows 10 1607 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-34328 windows 10 1809 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-34346 windows 10 1607 vulnerability
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-34349 windows 10 1809 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-41087 windows 10 1607 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-47282 visual studio code vulnerability
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Updated Jul 17, 2026
CVE-2026-49794 windows 10 1607 vulnerability
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
Updated Jul 17, 2026
CVE-2026-49807 windows 10 1809 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-50300 windows 10 1607 vulnerability
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-50316 windows 10 21h2 vulnerability
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-50350 windows 10 21h2 vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-54988 365 apps vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-56193 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-49177 windows 10 1607 vulnerability
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-50665 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-50670 windows 10 1809 vulnerability
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Updated Jul 17, 2026
CVE-2026-55023 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55027 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55028 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55035 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55044 365 apps vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-55045 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Updated Jul 17, 2026
CVE-2026-55046 365 apps vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55047 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55050 365 apps vulnerability
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-55139 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-56192 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-56195 365 apps vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Updated Jul 17, 2026
CVE-2026-57102 visual studio code vulnerability
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Updated Jul 17, 2026
CVE-2026-58529 windows 11 26h1 vulnerability
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Updated Jul 17, 2026
