All CVEs — page 200 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This flaw allows unauthenticated users to exploit broken authentication mechanisms in Headless Single Sign On versions 1.7.0 and earlier, leading to unauthorized access to sensitive resources.
The flaw allows unauthenticated attackers to execute arbitrary code on the server, leading to full control over the system.
The flaw is an unauthenticated broken authentication vulnerability in EduAdmin Booking versions 5.4.2 and earlier, allowing attackers to bypass authentication mechanisms and gain unauthorized access to the system.
The flaw allows attackers with log:view permission to read session tokens from the audit log, which can be used to gain full user access.