NA - CVE-2023-37910 - XWiki Platform is a generic wiki platform...
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment move support in version 14.0-rc-1 and prior to...
NA - CVE-2023-37911 - XWiki Platform is a generic wiki platform...
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, when a document...
NA - CVE-2023-37913 - XWiki Platform is a generic wiki platform...
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prior to versions 14.10.8 and 15.3-rc-1, triggering...
NA - CVE-2023-38041 - A logged in user may elevate its permissions by...
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition...
NA - CVE-2023-39219 - PingFederate Administrative Console dependency...
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
NA - CVE-2023-39231 - PingFederate using the PingOne MFA adapter...
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing registered device. A threat actor may be able to...
NA - CVE-2023-39732 - The leakage of the client secret in...
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.