Page 372 of 10616 results (0.141 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

An information leak in YKC Tokushima_awayokocho Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. • http://tokushimaawayokocho.com http://ykc.com https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39043.md • CWE-668: Exposure of Resource to Wrong Sphere •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

An information leak in Camp Style Project Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages. • http://camp.com https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39039.md • CWE-668: Exposure of Resource to Wrong Sphere •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Improper Privilege Management vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users.This issue affects . ... Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users.This issue affects Digital Yepas: before 1.0.1. • https://www.usom.gov.tr/bildirim/tr-23-0526 • CWE-269: Improper Privilege Management CWE-648: Incorrect Use of Privileged APIs •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a crafted http request. • https://fortiguard.com/psirt/FG-IR-23-126 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in versions up to, and including, 7.1.0 due to insufficient controls on the information retrievable via the shortcode. • https://plugins.trac.wordpress.org/browser/woocommerce-jetpack/tags/7.1.0/includes/shortcodes/class-wcj-general-shortcodes.php#L450 https://plugins.trac.wordpress.org/changeset/2966325/woocommerce-jetpack#file1 https://www.wordfence.com/threat-intel/vulnerabilities/id/a4cd49b2-ff93-4582-906b-b690d8472c38?source=cve • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •