CVE-2023-39980 – MXsecurity Authenticated Information Disclosure Due to SQL Injection
https://notcve.org/view.php?id=CVE-2023-39980
A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands. Se ha identificado una vulnerabilidad que permite la divulgación no autorizada de información autenticada en versiones de MXsecurity anteriores a la v1.0.1. Esta vulnerabilidad surge cuando los elementos especiales no se neutralizan correctamente, lo que permite a atacantes remotos alterar comandos SQL. • https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230403-mxsecurity-series-multiple-vulnerabilities • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-4714 – PlayTube Redirect information disclosure
https://notcve.org/view.php?id=CVE-2023-4714
The manipulation leads to information disclosure. ... Durch das Beeinflussen mit unbekannten Daten kann eine information disclosure-Schwachstelle ausgenutzt werden. ... PlayTube version 3.0.1 suffers from an information leakage vulnerability. • http://packetstormsecurity.com/files/174446/PlayTube-3.0.1-Information-Disclosure.html https://vuldb.com/?ctiid.238577 https://vuldb.com/?id.238577 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-23763 – Information disclosure in GitHub Enterprise Server leading to private repository leakage
https://notcve.org/view.php?id=CVE-2023-23763
An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to retain read access to an upstream repository after its visibility was changed to private. • https://docs.github.com/en/enterprise-server@3.6/admin/release-notes#3.6.18-security-fixes https://docs.github.com/en/enterprise-server@3.7/admin/release-notes#3.7.16-security-fixes https://docs.github.com/en/enterprise-server@3.8/admin/release-notes#3.8.9-security-fixes https://docs.github.com/en/enterprise-server@3.9/admin/release-notes#3.9.4-security-fixes • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-862: Missing Authorization •
CVE-2023-3950 – Cleartext Storage of Sensitive Information in GitLab
https://notcve.org/view.php?id=CVE-2023-3950
An information disclosure issue in GitLab EE affecting all versions from 16.2 prior to 16.2.5, and 16.3 prior to 16.3.1 allowed other Group Owners to see the Public Key for a Google Cloud Logging audit event streaming destination, if configured. • https://gitlab.com/gitlab-org/gitlab/-/issues/419675 https://hackerone.com/reports/2079154 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2023-40239
https://notcve.org/view.php?id=CVE-2023-40239
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. • https://publications.lexmark.com/publications/security-alerts/CVE-2023-40239.pdf • CWE-611: Improper Restriction of XML External Entity Reference •