Total
1125 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-43045 | 1 Ibm | 1 Sterling Partner Engagement Manager | 2023-10-28 | N/A | 7.5 HIGH |
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authentication. IBM X-Force ID: 266896. | |||||
CVE-2023-26580 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers. | |||||
CVE-2023-27261 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 6.5 MEDIUM |
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers. | |||||
CVE-2023-27375 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers. | |||||
CVE-2023-27376 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers. | |||||
CVE-2023-27256 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 5.3 MEDIUM |
Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by unauthenticated attackers. | |||||
CVE-2023-26574 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers. | |||||
CVE-2023-26573 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 9.1 CRITICAL |
Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials. | |||||
CVE-2023-26575 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers. | |||||
CVE-2023-26576 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers. | |||||
CVE-2023-26579 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 5.3 MEDIUM |
Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff information by unauthenticated attackers. | |||||
CVE-2023-26571 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers. | |||||
CVE-2023-26570 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers. | |||||
CVE-2023-27259 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers. | |||||
CVE-2023-27258 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers. | |||||
CVE-2023-27257 | 1 Idattend | 1 Idweb | 2023-10-28 | N/A | 7.5 HIGH |
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers. | |||||
CVE-2023-0919 | 1 Kavitareader | 1 Kavita | 2023-10-27 | N/A | 3.5 LOW |
Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0. | |||||
CVE-2023-43271 | 1 70mai | 2 A500s, A500s Firmware | 2023-10-16 | N/A | 9.1 CRITICAL |
Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols. | |||||
CVE-2023-44116 | 1 Huawei | 2 Emui, Harmonyos | 2023-10-15 | N/A | 9.8 CRITICAL |
Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized. | |||||
CVE-2023-4884 | 1 Open5gs | 1 Open5gs | 2023-10-05 | N/A | 7.5 HIGH |
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication. |