Page 435 of 10627 results (0.032 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys. Divulgación de información en encuestas protegidas mediante contraseña en Data Illusion Survey Software Solutions NGSurvey v2.4.28 e inferiores permite a los atacantes ver la contraseña para acceder y enviar encuestas arbitrariamente. • https://github.com/WodenSec/CVE-2022-46484 • CWE-922: Insecure Storage of Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. • https://github.com/LavaLite/cms https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-36983 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. • https://github.com/LavaLite/cms https://github.com/M19O/Security-Advisories/tree/main/CVE-2023-36984 •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190744. IBM TRIRIGA v3.0, v4.0 y v4.4 podrían permitir a un atacante remoto obtener información sensible cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría utilizarse en ataques posteriores contra el sistema. • https://exchange.xforce.ibmcloud.com/vulnerabilities/190744 https://www.ibm.com/support/pages/node/7015393 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 7.1EPSS: 0%CPEs: -EXPL: 0

The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. •