2023 CVE Vulnerabilities

31,400 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-27376HIGH7.5Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 an...
CVE-2023-27375HIGH7.5Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 an...
CVE-2023-27262CRITICAL9.1Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier...
CVE-2023-27261MEDIUM6.5Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allow...
CVE-2023-27260CRITICAL9.1Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier...
CVE-2023-27259HIGH7.5Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows e...
CVE-2023-27258HIGH7.5Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier all...
CVE-2023-27257HIGH7.5Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows...
CVE-2023-27256MEDIUM5.3Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval ...
CVE-2023-27255CRITICAL9.1Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier ...
CVE-2023-27254CRITICAL9.1Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allo...
CVE-2023-26584CRITICAL9.1Unauthenticated SQL injection in the GetStudentInconsistencies method in IDAttend’s IDWeb application 3.1.052 and ea...
CVE-2023-26583CRITICAL9.1Unauthenticated SQL injection in the GetCurrentPeriod method in IDAttend’s IDWeb application 3.1.052 and earlier allo...
CVE-2023-26582CRITICAL9.1Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier al...
CVE-2023-26581CRITICAL9.1Unauthenticated SQL injection in the GetVisitors method in IDAttend’s IDWeb application 3.1.052 and earlier allows extr...
CVE-2023-26580HIGH7.5Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present...
CVE-2023-26579MEDIUM5.3Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff inform...
CVE-2023-26578HIGH8.8Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload d...
CVE-2023-26577MEDIUM5.4Stored cross-site scripting in the IDAttend’s IDWeb application 3.1.052 and earlier allows attackers to hijack the brows...
CVE-2023-26576HIGH7.5Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext...
CVE-2023-26575HIGH7.5Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows ext...
CVE-2023-26574HIGH7.5Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extractio...
CVE-2023-26573CRITICAL9.1Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service ...
CVE-2023-26572CRITICAL9.1Unauthenticated SQL injection in the GetExcursionList method in IDAttend’s IDWeb application 3.1.052 and earlier allows ...
CVE-2023-26571HIGH7.5Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modific...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now