Vulnerabilities (CVE)

Filtered by CWE-306
Total 1459 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27375 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
CVE-2023-27290 1 Ibm 1 Observability With Instana 2024-11-21 N/A 9.1 CRITICAL
Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.
CVE-2023-27267 1 Sap 1 Diagnostics Agent 2024-11-21 N/A 9.0 CRITICAL
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
CVE-2023-27261 1 Idattend 1 Idweb 2024-11-21 N/A 5.3 MEDIUM
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.
CVE-2023-27259 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.
CVE-2023-27258 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.
CVE-2023-27257 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers.
CVE-2023-27256 1 Idattend 1 Idweb 2024-11-21 N/A 5.8 MEDIUM
Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by unauthenticated attackers.
CVE-2023-26580 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.
CVE-2023-26579 1 Idattend 1 Idweb 2024-11-21 N/A 5.3 MEDIUM
Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff information by unauthenticated attackers.
CVE-2023-26576 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
CVE-2023-26575 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.
CVE-2023-26574 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
CVE-2023-26573 1 Idattend 1 Idweb 2024-11-21 N/A 8.2 HIGH
Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.
CVE-2023-26571 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers.
CVE-2023-26570 1 Idattend 1 Idweb 2024-11-21 N/A 7.5 HIGH
Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
CVE-2023-25780 1 Status 1 Powerbpm 2024-11-21 N/A 5.7 MEDIUM
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
CVE-2023-25570 1 Apolloconfig 1 Apollo 2024-11-21 N/A 7.5 HIGH
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka directly to mock apollo-configservice and apollo-adminservice. Login authentication for eureka was added in version 2.1.0. As a workaround, avoid exposing apollo-configservice to the internet.
CVE-2023-25493 2024-11-21 N/A 6.7 MEDIUM
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.
CVE-2023-24934 1 Microsoft 1 Malware Protection Platform 2024-11-21 N/A 6.2 MEDIUM
Microsoft Defender Security Feature Bypass Vulnerability