Show filters
588 Total Results
Displaying 131-140 of 588
Sort by:
Attacker Value
Unknown

CVE-2023-39737

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Attacker Value
Unknown

CVE-2023-39736

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Attacker Value
Unknown

CVE-2023-39735

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Attacker Value
Unknown

CVE-2023-39734

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Attacker Value
Unknown

CVE-2023-39733

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Attacker Value
Unknown

CVE-2023-39732

Disclosure Date: October 25, 2023 (last updated November 01, 2023)
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Attacker Value
Unknown

CVE-2023-43794

Disclosure Date: October 17, 2023 (last updated October 25, 2023)
Nocodb is an open source Airtable alternative. Affected versions of nocodb contain a SQL injection vulnerability, that allows an authenticated attacker with creator access to query the underlying database. By supplying a specially crafted payload to the given an attacker can inject arbitrary SQL queries to be executed. Since this is a blind SQL injection, an attacker may need to use time-based payloads which would include a function to delay execution for a given number of seconds. The response time indicates, whether the result of the query execution was true or false. Depending on the result, the HTTP response will be returned after a given number of seconds, indicating TRUE, or immediately, indicating FALSE. In that way, an attacker can reveal the data present in the database. This vulnerability has been addressed in version 0.111.0. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as `GHSL-2023-141`.
Attacker Value
Unknown

CVE-2023-4834

Disclosure Date: October 16, 2023 (last updated October 25, 2023)
In Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implemented access validation allows an authenticated, low privileged attacker to gain read access to limited, non-critical device information in his account he should not have access to.
Attacker Value
Unknown

CVE-2023-5554

Disclosure Date: October 12, 2023 (last updated October 18, 2023)
Lack of TLS certificate verification in log transmission of a financial module within LINE Client for iOS prior to 13.16.0.
Attacker Value
Unknown

CVE-2023-43297

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.