Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Secure Client MEDIUM 6.8
CVE-2024-20391

A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an …

Fix: 5.1.3.62+
Fix from $1,600 2024-05-15
Unclassified HIGH 7.4
CVE-2023-5935

When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks aut…

Mitigation only
Fix from $1,950 2024-05-15
Ruggedcom Crossbow HIGH 7.5
CVE-2024-27942

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect …

Fix: 5.5+
Fix from $1,950 2024-05-14
Powerpanel CRITICAL 9.8
CVE-2024-32735EPSS 7%

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote…

Fix: 2.8.3+
Fix from $2,300 2024-05-14
Unclassified HIGH 7.6
CVE-2022-32503

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the devi…

Mitigation only
Fix from $1,950 2024-05-14
Ssl Zen MEDIUM 6.5
CVE-2024-1076

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .h…

Fix: 4.6.0+
Fix from $1,600 2024-05-08
Brocade Sannav HIGH 7.8
CVE-2024-2860

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing…

Fix: 2.3.0a+
Fix from $1,950 2024-05-08
Dap 2622 Firmware MEDIUM 5.4
CVE-2023-37325

D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized cha…

Mitigation only
Fix from $1,600 2024-05-07
Xr1000 Firmware MEDIUM 6.5
CVE-2021-34983

NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-a…

Fix: 1.0.0.62 / 1.0.0.64+
Fix from $1,600 2024-05-07
Forticlient HIGH 7.6
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redi…

Fix: 1.5.1.25 / 3.7.0.134+
Fix from $1,950 2024-05-06
Viewpower HIGH 7.5
CVE-2023-51587EPSS 36%

Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t…

Mitigation only
Fix from $1,950 2024-05-03
G416 Firmware HIGH 8.8
CVE-2023-50199

D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attack…

Fix: 1.09b01+
Fix from $1,950 2024-05-03
D View 8 HIGH 7.5
CVE-2023-44413

D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a deni…

Mitigation only
Fix from $1,950 2024-05-03
Webpanel CRITICAL 9.8
CVE-2023-42121

Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Mitigation only
Fix from $2,300 2024-05-03
Dap 1325 Firmware MEDIUM 6.5
CVE-2023-41186

D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to access vario…

Fix: 1.09b03+
Fix from $1,600 2024-05-03
Dap 1325 Firmware HIGH 8.8
CVE-2023-41187

D-Link DAP-1325 HNAP Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi…

Fix: 1.09b03+
Fix from $1,950 2024-05-03
Rbr760 Firmware HIGH 8.8
CVE-2023-41183EPSS 15%

NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affec…

Fix: 6.3.8.5+
Fix from $1,950 2024-05-03
Scada Data Gateway MEDIUM 5.3
CVE-2023-39466

Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attac…

Mitigation only
Fix from $1,600 2024-05-03
Scada Data Gateway CRITICAL 9.8
CVE-2023-39457

Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on a…

Mitigation only
Fix from $2,300 2024-05-03
Ignition HIGH 8.8
CVE-2023-38123

Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability. This vulnerabilit…

Fix: 8.1.26+
Fix from $1,950 2024-05-03
Rax30 Firmware MEDIUM 6.5
CVE-2023-27357

NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose s…

Fix: 1.0.10.94+
Fix from $1,600 2024-05-03
Ur32l Firmware HIGH 8.8
CVE-2023-47166

A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request…

Mitigation only
Fix from $1,950 2024-05-01
Myqnapcloud Link CRITICAL 9.9
CVE-2024-32764

A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allo…

Fix: 2.4.51+
Fix from $2,300 2024-04-26
Build App Online CRITICAL 9.8
CVE-2023-51478

Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a thro…

Fix: 1.0.20+
Fix from $2,300 2024-04-25
Unclassified HIGH 7.5
CVE-2024-1491

The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system …

Mitigation only
Fix from $1,950 2024-04-18
Unclassified MEDIUM 5.3
CVE-2024-21846

An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET request to the command.cgi gatew…

Mitigation only
Fix from $1,600 2024-04-18
Hospitality Simphony CRITICAL 9.8
CVE-2024-21014

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported…

Fix: after 19.5.4
Fix from $2,300 2024-04-16
Weblogic Server HIGH 7.5
CVE-2024-21006EPSS 8%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2024-04-16
Weblogic Server HIGH 7.5
CVE-2024-21007

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Mitigation only
Fix from $1,950 2024-04-16
Unclassified HIGH 7.5
CVE-2023-4857

An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that c…

Mitigation only
Fix from $1,950 2024-04-15