CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-27261

    Last Modified: 21 Nov 2024

    Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-27377

    Last Modified: 21 Nov 2024

    Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-27376

    Last Modified: 21 Nov 2024

    Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-27375

    Last Modified: 21 Nov 2024

    Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-27259

    Last Modified: 21 Nov 2024

    Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-27258

    Last Modified: 21 Nov 2024

    Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-27257

    Last Modified: 21 Nov 2024

    Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers.

    Published: 25 Oct 2023
    5.8
    Medium

    CVE-2023-27256

    Last Modified: 21 Nov 2024

    Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-27255

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-27254

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-26584

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the GetStudentInconsistencies method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-26583

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the GetCurrentPeriod method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-26582

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-26581

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the GetVisitors method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-26580

    Last Modified: 21 Nov 2024

    Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.

    Published: 25 Oct 2023
    5.3
    Medium

    CVE-2023-26579

    Last Modified: 21 Nov 2024

    Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff information by unauthenticated attackers.

    Published: 25 Oct 2023
    8.8
    High

    CVE-2023-26578

    Last Modified: 21 Nov 2024

    Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-26577

    Last Modified: 21 Nov 2024

    Stored cross-site scripting in the IDAttend’s IDWeb application 3.1.052 and earlier allows attackers to hijack the browsing session of the logged in user.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-26576

    Last Modified: 21 Nov 2024

    Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-26575

    Last Modified: 21 Nov 2024

    Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-26574

    Last Modified: 21 Nov 2024

    Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

    Published: 25 Oct 2023
    8.2
    High

    CVE-2023-26573

    Last Modified: 21 Nov 2024

    Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-26572

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the GetExcursionList method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    —
    Unknown

    CVE-2023-46716

    Last Modified: 6 May 2025

    Not used

    Published: 25 Oct 2023
    —
    Unknown

    CVE-2023-46719

    Last Modified: 17 Mar 2025

    Not used

    Published: 25 Oct 2023
    —
    Unknown

    CVE-2023-46721

    Last Modified: 17 Mar 2025

    Not used

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-26571

    Last Modified: 21 Nov 2024

    Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-26570

    Last Modified: 21 Nov 2024

    Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-26569

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-26568

    Last Modified: 21 Nov 2024

    Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

    Published: 25 Oct 2023
    7.3
    High

    CVE-2023-3010

    Last Modified: 12 Jun 2025

    Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.

    Published: 25 Oct 2023
    8.8
    High

    CVE-2023-5311

    Last Modified: 8 Apr 2026

    The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htaccess files located in a site's root directory or /wp-content and /wp-includes folders and achieve remote code execution. CVE-2023-46623 appears to be a duplicate of this issue.

    Published: 25 Oct 2023
    4.3
    Medium

    CVE-2023-34056

    Last Modified: 21 Nov 2024

    vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-34048

    Last Modified: 30 Oct 2025

    vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

    Published: 25 Oct 2023
    —
    Unknown

    CVE-2023-45848

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 25 Oct 2023
    —
    Unknown

    CVE-2023-45214

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published: 25 Oct 2023
    4.9
    Medium

    CVE-2023-46158

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268775.

    Published: 25 Oct 2023
    2.6
    Low

    CVE-2023-34085

    Last Modified: 21 Nov 2024

    When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-39219

    Last Modified: 12 Jun 2025

    PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests

    Published: 25 Oct 2023
    8.1
    High

    CVE-2023-37283

    Last Modified: 21 Nov 2024

    Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter

    Published: 25 Oct 2023
    5.3
    Medium

    CVE-2023-46135

    Last Modified: 21 Nov 2024

    rs-stellar-strkey is a Rust lib for encode/decode of Stellar Strkeys. A panic vulnerability occurs when a specially crafted payload is used.`inner_payload_len` should not above 64. This vulnerability has been patched in version 0.0.8.

    Published: 25 Oct 2023
    7
    High

    CVE-2023-38041

    Last Modified: 7 Mar 2025

    A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

    Published: 25 Oct 2023
    5.3
    Medium

    CVE-2023-41721

    Last Modified: 21 Nov 2024

    Instances of UniFi Network Application that (i) are run on a UniFi Gateway Console, and (ii) are versions 7.5.176. and earlier, implement device adoption with improper access control logic, creating a risk of access to device configuration information by a malicious actor with preexisting access to the network. Affected Products: UDM UDM-PRO UDM-SE UDR UDW Mitigation: Update UniFi Network to Version 7.5.187 or later.

    Published: 25 Oct 2023
    5.3
    Medium

    CVE-2023-46123

    Last Modified: 25 Mar 2025

    jumpserver is an open source bastion machine, professional operation and maintenance security audit system that complies with 4A specifications. A flaw in the Core API allows attackers to bypass password brute-force protections by spoofing arbitrary IP addresses. By exploiting this vulnerability, attackers can effectively make unlimited password attempts by altering their apparent IP address for each request. This vulnerability has been patched in version 3.8.0.

    Published: 25 Oct 2023
    7.5
    High

    CVE-2023-46119

    Last Modified: 21 Nov 2024

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.

    Published: 25 Oct 2023
    7
    High

    CVE-2023-5574

    Last Modified: 23 Jun 2026

    A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during shutdown or reset of the Xvfb server, allowing for possible escalation of privileges or denial of service.

    Published: 25 Oct 2023
    4.7
    Medium

    CVE-2023-5380

    Last Modified: 23 Jun 2026

    A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

    Published: 25 Oct 2023
    7.8
    High

    CVE-2023-5367

    Last Modified: 23 Jun 2026

    A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.

    Published: 25 Oct 2023
    9.1
    Critical

    CVE-2023-46233

    Last Modified: 23 Jun 2026

    crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it both defaults to SHA1, a cryptographic hash algorithm considered insecure since at least 2005, and defaults to one single iteration, a 'strength' or 'difficulty' value specified at 1,000 when specified in 1993. PBKDF2 relies on iteration count as a countermeasure to preimage and collision attacks. If used to protect passwords, the impact is high. If used to generate signatures, the impact is high. Version 4.2.0 contains a patch for this issue. As a workaround, configure crypto-js to use SHA256 with at least 250,000 iterations.

    Published: 25 Oct 2023
    9.8
    Critical

    CVE-2023-46418

    Last Modified: 21 Nov 2024

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.

    Published: 25 Oct 2023