Page 57 of 10576 results (0.274 seconds)

CVSS: 5.0EPSS: 0%CPEs: -EXPL: 0

On successful exploitation this can result in information disclosure. • https://me.sap.com/notes/3458789 https://url.sap/sapsecuritypatchday • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 0

On successful exploitation this can result in information disclosure. • https://me.sap.com/notes/3467377 https://url.sap/sapsecuritypatchday • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 6.9EPSS: 0%CPEs: 1EXPL: 0

SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities. SAP Landscape Management permite a un usuario autenticado leer datos confidenciales revelados por la respuesta de Provider Definition REST. La explotación exitosa puede causar un gran impacto en la confidencialidad de las entidades gestionadas. • https://me.sap.com/notes/3466801 https://url.sap/sapsecuritypatchday • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.1EPSS: 0%CPEs: -EXPL: 0

A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. • https://github.com/stitionai/devika/commit/6acce21fb08c3d1123ef05df6a33912bf0ee77c2 https://huntr.com/bounties/7ffeb896-27c8-429d-b241-4f7d6dda0afd • CWE-346: Origin Validation Error •

CVSS: -EPSS: 0%CPEs: -EXPL: 0

vaeThink 1.0.2 is vulnerable to Information Disclosure via the system backend,access management administrator function. • https://gist.github.com/fltys/b2c430bca85c97211010bdc602437978 https://github.com/tingyuu/vaeThink •