Security Risk Category

Information Disclosure Security Risks — Page 3

Published vulnerability pages connected to Information Disclosure. Each page keeps one canonical URL and focused remediation guidance.

320 published Information Disclosure risks

Information Disclosure risks

Showing 73–108 of 320 published risks.

mediumEPSS 0.009

CVE-2026-58539 windows 10 1607 vulnerability

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58539windowsinformation-disclosure

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-47979 media encoder vulnerability

Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47979information-disclosure

Updated Jul 17, 2026

highEPSS 0.004

CVE-2026-48295 c2pa vulnerability

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.

CVE-2026-48295information-disclosure

Updated Jul 17, 2026

medium

CVE-2025-43892 in Fortinet FortiProxy

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.

CVE-2025-43892network-securityinformation-disclosurememory-corruption

Updated Jul 16, 2026

high

CVE-2025-53379 in Fortinet FortiAuthenticator

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.

CVE-2025-53379network-securityinformation-disclosure

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-50678 in Microsoft 365 Apps

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50678microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-50697 in Microsoft Windows

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50697windowsmicrosoftinformation-disclosureprivilege-escalation

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54111 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-54111windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.005

CVE-2026-48580 in Microsoft 365 Apps

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-48580microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-50408 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-50408microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.004

CVE-2026-55031 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55031microsoftremote-code-executioninformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55058 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55058microsoftremote-code-executioninformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-55121 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-55121microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-55122 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55122microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-55138 in Microsoft 365 Apps

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55138microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-55898 in Microsoft 365 Apps

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-55898microsoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

low

CVE-2026-15642 in Devolutions Server

Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.

CVE-2026-15642web-applicationinformation-disclosure

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15766 in Google Chrome

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15766browserinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15770 in Google Chrome

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15770browserinformation-disclosurememory-corruption

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-15771 in Google Chrome

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15771browserwindowsinput-validationinformation-disclosure

Updated Jul 16, 2026

criticalEPSS 0.067

CVE-2026-48318 in Adobe ColdFusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48318web-applicationinformation-disclosurepath-traversalfile-write

Updated Jul 16, 2026

highEPSS 0.006

CVE-2026-48328 in Adobe ColdFusion

ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48328web-applicationinput-validationauthorization-bypassinformation-disclosure

Updated Jul 16, 2026

highEPSS 0.120

CVE-2026-48332 in Adobe ColdFusion

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48332web-applicationauthorization-bypassinformation-disclosuressrf

Updated Jul 16, 2026

mediumEPSS 0.003

CVE-2026-48338 in Adobe ColdFusion

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48338web-applicationinformation-disclosurepath-traversalfile-write

Updated Jul 16, 2026

mediumEPSS 0.004

CVE-2026-46635 in Twig

Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with column in allowedFilters to read properties that are not in the sandbox allowlist. This issue is fixed in version 3.26.0.

CVE-2026-46635phpauthorization-bypassinformation-disclosure

Updated Jul 16, 2026

highEPSS 0.004

CVE-2026-46639 in Twig

Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a sandboxed Twig template to read public properties or invoke public getters on objects passed to the template engine. This issue is fixed in version 3.26.0.

CVE-2026-46639phpauthorization-bypassinformation-disclosure

Updated Jul 16, 2026

highEPSS 0.003

CVE-2026-56287 in Apache Fineract

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclose arbitrary files readable by the database process via the LOAD_FILE() function. Users are recommended to upgrade to a version containing the fix

CVE-2026-56287javaapi-securitysql-injectioninformation-disclosure

Updated Jul 16, 2026

high

CVE-2026-40633 in Dell PowerScale OneFS

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

CVE-2026-40633network-securityinformation-disclosure

Updated Jul 16, 2026

low

CVE-2026-40956 in Absolute Secure Access

CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.

CVE-2026-40956network-securityinformation-disclosure

Updated Jul 16, 2026

medium

CVE-2026-40957 in Absolute Secure Access

o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.

CVE-2026-40957network-securityweb-applicationinformation-disclosure

Updated Jul 16, 2026

mediumEPSS 0.002

List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute

The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full content, excerpts, dates, authors, and custom-field metadata of other users' pending-review, scheduled, and trashed posts by embedding a crafted [catlist] shortcode in their own draft and previewing it. This vulnerability is a bypass of the incomplete fix introduced for CVE-2025-11377 in version 0.93.0.

CVE-2025-11377CVE-2026-12434wordpressauthorization-bypassinformation-disclosure

Updated Jul 16, 2026

medium

WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter

The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. wp_unslash() is applied to the raw POST body before parse_str() decomposes it, stripping WordPress magic-quotes protection and leaving attacker-controlled values fully unescaped prior to reaching the SQL sink.

CVE-2026-15727wordpresssql-injectioninformation-disclosure

Updated Jul 16, 2026

high

Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2026-12753wordpresswoocommercesql-injectioninformation-disclosure

Updated Jul 16, 2026

medium

SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Although esc_sql() and sanitize_text_field() are applied, neither neutralizes SQL keywords, commas, parentheses, or subquery syntax in an unquoted ORDER BY context, leaving the clause fully attacker-controlled.

CVE-2026-15445wordpresssql-injectioninformation-disclosure

Updated Jul 16, 2026

high

Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the targeted form to not enforce login (so publicly accessible), which allows the unauthenticated attacker to reach the process_send_resume_link endpoint and supply an arbitrary recipient email address to receive the traversal-retrieved file as a notification attachment.

CVE-2026-12997wordpressinformation-disclosurepath-traversalfile-write

Updated Jul 16, 2026

medium

Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter

The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient preparation on the existing SQL query built in qsm_options_questions_tab_content() at line 143, where the stored page IDs are interpolated into an IN() clause via implode() with no $wpdb->prepare() and no integer casting. This makes it possible for authenticated attackers, with Author-level access and above (who can own a quiz they are entitled to edit), to plant a SQL payload that is executed second-order whenever any user (including an administrator) views the quiz's Questions tab, allowing them to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2026-13767wordpresssql-injectioninformation-disclosure

Updated Jul 16, 2026