Show filters
1,100 Total Results
Displaying 421-430 of 1,100
Sort by:
Attacker Value
Unknown
CVE-2023-2781
Disclosure Date: June 03, 2023 (last updated February 25, 2025)
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Allow Automatic Login After Successful Verification setting to be enabled, which it is not by default.
0
Attacker Value
Unknown
CVE-2023-34094
Disclosure Date: June 02, 2023 (last updated February 25, 2025)
ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 20230526 and prior allows unauthorized access to the config.json file of the privately deployed ChuanghuChatGPT project, when authentication is not configured. The attacker can exploit this vulnerability to steal the API keys in the configuration file. The vulnerability has been fixed in commit bfac445. As a workaround, setting up access authentication can help mitigate the vulnerability.
0
Attacker Value
Unknown
CVE-2022-4240
Disclosure Date: May 30, 2023 (last updated February 25, 2025)
Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless version 322.1
0
Attacker Value
Unknown
CVE-2022-36249
Disclosure Date: May 29, 2023 (last updated February 25, 2025)
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.
0
Attacker Value
Unknown
CVE-2023-33247
Disclosure Date: May 26, 2023 (last updated February 25, 2025)
Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the Talend Data Catalog server.)
0
Attacker Value
Unknown
CVE-2023-31227
Disclosure Date: May 26, 2023 (last updated February 25, 2025)
The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentiality.
0
Attacker Value
Unknown
CVE-2023-0116
Disclosure Date: May 26, 2023 (last updated February 25, 2025)
The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability.
0
Attacker Value
Unknown
CVE-2023-31594
Disclosure Date: May 25, 2023 (last updated February 25, 2025)
IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.
0
Attacker Value
Unknown
CVE-2023-1837
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR Server: before 8.0 (with enabled Legacy APIs)
0
Attacker Value
Unknown
CVE-2023-23545
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the product settings without authentication. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).
0