So basically if I put somebody's email address I could know the sites they have logged in in the past? And then I can use the leak and get access to their account? Shouldn't this information be mailed to the email address queried rather than displaying upfront
However, in most leaks, you can't just use the information as the passwords are (hopefully) hashed/salted. That said, it is trivial to crack md5 if passwords are stored using that method.
Also, not all leaks contain passwords, some might just be lists of email addresses or other information.