Skip to content
Threat Feed

Tag

Info-Disclosure

5 briefs RSS
high advisory

Information Disclosure in SiYuan Kernel Enabling Offline Password Cracking

An information disclosure vulnerability in SiYuan's API allows unauthorized remote readers to retrieve cryptographic material necessary for offline, unthrottled GPU-based cracking of encrypted notebook master passwords.

SiYuan Kernel +5 info-disclosure cve cryptanalysis authentication-bypass webserver vulnerability session-forgery credential-disclosure +3
4r 8t 1c updated
high advisory

Remote Code Execution in GitPython via Git Config Injection

GitPython versions before 3.1.59 contain a vulnerability where improper sanitization of multi-line configuration values allows attackers to inject arbitrary git directives, leading to remote code execution.

GitPython +2 vulnerability path-traversal supply-chain info-disclosure local-file-inclusion
4t 1c updated
critical advisory

Arbitrary XML Schema Definition Processing in guardrails-detectors Leads to SSRF and Local File Read

A flaw in the 'file_type' content detector of 'guardrails-detectors' allows a remote attacker to provide an arbitrary XML Schema Definition (XSD) string, leading to server-side request forgery (SSRF) and local file reads, potentially exposing sensitive information such as cloud provider credentials or granting access to internal network services.

guardrails-detectors vulnerability ssrf local-file-read info-disclosure guardrails
3t 1c
high advisory

Multiple Vulnerabilities Discovered in Wireshark Leading to DoS and Data Confidentiality Compromise

Multiple vulnerabilities (CVE-2026-15163 through CVE-2026-15174) have been discovered in Wireshark, impacting versions 4.6.x prior to 4.6.7 and versions prior to 4.4.17, which could allow a remote attacker to cause a denial of service and compromise data confidentiality.

Wireshark 4.6.x +1 vulnerability wireshark dos info-disclosure product-vulnerability
2t 5c
high advisory

WordPress Easy PayPal Events & Tickets Plugin Information Disclosure Vulnerability

An information disclosure vulnerability in the Easy PayPal Events & Tickets WordPress plugin (versions 1.3 and earlier) allows unauthenticated attackers to enumerate and retrieve all customer order records via the scan_qr.php endpoint.

Easy PayPal Events & Tickets plugin wordpress info-disclosure cve-2026-41471 unauthenticated enumeration
2r 1t 1c