2023 CVE Vulnerabilities
31,400 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27376 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 an... |
| CVE-2023-27375 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 an... |
| CVE-2023-27262 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier... |
| CVE-2023-27261 | MEDIUM | 6.5 | 0.5% | Oct 25, 2023 | Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allow... |
| CVE-2023-27260 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier... |
| CVE-2023-27259 | HIGH | 7.5 | 0.5% | Oct 25, 2023 | Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows e... |
| CVE-2023-27258 | HIGH | 7.5 | 0.5% | Oct 25, 2023 | Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier all... |
| CVE-2023-27257 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows... |
| CVE-2023-27256 | MEDIUM | 5.3 | 0.6% | Oct 25, 2023 | Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval ... |
| CVE-2023-27255 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier ... |
| CVE-2023-27254 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allo... |
| CVE-2023-26584 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetStudentInconsistencies method in IDAttend’s IDWeb application 3.1.052 and ea... |
| CVE-2023-26583 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetCurrentPeriod method in IDAttend’s IDWeb application 3.1.052 and earlier allo... |
| CVE-2023-26582 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier al... |
| CVE-2023-26581 | CRITICAL | 9.1 | 0.6% | Oct 25, 2023 | Unauthenticated SQL injection in the GetVisitors method in IDAttend’s IDWeb application 3.1.052 and earlier allows extr... |
| CVE-2023-26580 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present... |
| CVE-2023-26579 | MEDIUM | 5.3 | 0.5% | Oct 25, 2023 | Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff inform... |
| CVE-2023-26578 | HIGH | 8.8 | 1.5% | Oct 25, 2023 | Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload d... |
| CVE-2023-26577 | MEDIUM | 5.4 | 0.4% | Oct 25, 2023 | Stored cross-site scripting in the IDAttend’s IDWeb application 3.1.052 and earlier allows attackers to hijack the brows... |
| CVE-2023-26576 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext... |
| CVE-2023-26575 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext... |
| CVE-2023-26574 | HIGH | 7.5 | 0.7% | Oct 25, 2023 | Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extractio... |
| CVE-2023-26573 | CRITICAL | 9.1 | 0.7% | Oct 25, 2023 | Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service ... |
| CVE-2023-26572 | CRITICAL | 9.1 | 0.8% | Oct 25, 2023 | Unauthenticated SQL injection in the GetExcursionList method in IDAttend’s IDWeb application 3.1.052 and earlier allows ... |
| CVE-2023-26571 | HIGH | 7.5 | 0.6% | Oct 25, 2023 | Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modific... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now