All CosmicBytez Labs articles tagged #Information Disclosure, across news, security advisories, how-to guides, and projects.
docker-socket-proxy's CONTAINERS guard bypassed via GET requests to /archive, /export, /logs, and /top, exposing arbitrary file reads.
SiYuan before 3.7.4 exposes Go pprof debug endpoints unauthenticated, leaking in-memory secrets including API keys and auth codes.
A high-severity origin validation error in Microsoft Edge (Chromium-based) enables an unauthenticated remote attacker to disclose sensitive information across origins. Users should update Edge immediately.
A high-severity access control flaw in Microsoft Edge (Chromium-based) allows unauthenticated remote attackers to access files or directories that should be protected. Update to the latest Edge version immediately.
A critical CVSS 9.8 vulnerability in M3WebServer hard-codes backend API keys in the production build. Attackers intercept them through verbose error handling…
CVE-2026-39079 is a CVSS 7.5 (High) information disclosure vulnerability in the PrestaShop upsshipping module affecting all versions through 2.4.0. Remote...
A critical vulnerability in Ivanti Xtraction before version 2026.2 allows remote authenticated attackers to read sensitive files and write arbitrary HTML...
A CVSS 10.0 critical vulnerability in steam-trader 2.1.1 exposes Steam account credentials, identity secrets, and shared secrets to unauthenticated remote...
A critical unauthenticated information disclosure vulnerability in SiYuan, the personal knowledge management system, allows remote attackers to retrieve...
ZKTeco ZKBioSecurity 3.0 allows unauthenticated attackers to enumerate valid usernames by submitting partial character strings to the...
CISA has added CVE-2025-47813, a medium-severity information disclosure flaw in Wing FTP Server, to its KEV catalog after confirming active exploitation...