Show filters
969 Total Results
Displaying 271-280 of 969
Sort by:
Attacker Value
Unknown

CVE-2023-35873

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.
Attacker Value
Unknown

CVE-2023-35872

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.
Attacker Value
Unknown

CVE-2023-30643

Disclosure Date: July 06, 2023 (last updated February 25, 2025)
Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.
Attacker Value
Unknown

CVE-2023-22906

Disclosure Date: July 04, 2023 (last updated February 25, 2025)
Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.
Attacker Value
Unknown

CVE-2023-36347

Disclosure Date: June 30, 2023 (last updated February 25, 2025)
A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
Attacker Value
Unknown

CVE-2023-2834

Disclosure Date: June 30, 2023 (last updated February 25, 2025)
The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Attacker Value
Unknown

CVE-2023-35830

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without the need for authentication, giving an attacker arbitrary remote code execution over LTE / 4G network via SMS.
Attacker Value
Unknown

CVE-2023-34761

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter.
Attacker Value
Unknown

CVE-2023-35854

Disclosure Date: June 20, 2023 (last updated February 25, 2025)
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."
Attacker Value
Unknown

CVE-2022-48496

Disclosure Date: June 19, 2023 (last updated February 25, 2025)
Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious apps to become pre-authorized.