Show filters
885 Total Results
Displaying 241-250 of 885
Sort by:
Attacker Value
Unknown

CVE-2023-27267

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
Attacker Value
Unknown

CVE-2023-24527

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability and integrity.
Attacker Value
Unknown

CVE-2023-28697

Disclosure Date: March 31, 2023 (last updated February 24, 2025)
Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.
Attacker Value
Unknown

CVE-2020-14140

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is caused by the lack of access control policies on some API interfaces. Attackers can exploit this vulnerability to enter the background and execute background command injection.
Attacker Value
Unknown

CVE-2022-36983

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetSettings class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-15919.
Attacker Value
Unknown

CVE-2022-27645

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within readycloud_control.cgi. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15762.
Attacker Value
Unknown

CVE-2023-28326

Disclosure Date: March 28, 2023 (last updated February 24, 2025)
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room
Attacker Value
Unknown

CVE-2022-48291

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
Attacker Value
Unknown

CVE-2023-1140

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.
Attacker Value
Unknown

CVE-2023-28470

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.