Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Feverwarn Firmware MEDIUM 6.5
CVE-2023-6221

The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC…

No fix yet
Fix from $1,600 2024-02-01
Feverwarn Firmware HIGH 7.5
CVE-2023-49115

MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.

Mitigation only
Fix from $1,950 2024-02-01
Powerscale Onefs HIGH 7.8
CVE-2024-22449

Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local …

Fix: 9.6.1+
Fix from $1,950 2024-02-01
Ezsocket HIGH 7.5
CVE-2023-6942

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GO…

Mitigation only
Fix from $1,950 2024-01-30
Arris Surfboard Sbg6950ac2 Firmware CRITICAL 9.8
CVE-2024-23618

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to…

Mitigation only
Fix from $2,300 2024-01-26
Junos HIGH 7.5
CVE-2024-21619

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerabili…

Fix: 20.4+
Fix from $1,950 2024-01-25
Actinas Sl 2u 8 Rdx Firmware CRITICAL 9.1
CVE-2023-51947

Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data w…

Mitigation only
Fix from $2,300 2024-01-19
Armoury Crate CRITICAL 9.8
CVE-2023-5716

ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HT…

Fix: 4.1.0.8+
Fix from $2,300 2024-01-19
Language Server Protocol Integration CRITICAL 9.8
CVE-2024-22415

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Serve…

Fix: 2.2.2+
Fix from $2,300 2024-01-18
Global Site Selector CRITICAL 9.8
CVE-2024-22212

Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem…

Fix: 1.4.1 / 2.1.2+
Fix from $2,300 2024-01-18
Cmc HIGH 7.5
CVE-2023-5253

A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an un…

Fix: 23.3.0+
Fix from $1,950 2024-01-15
Archive Storage Manager MEDIUM 5.3
CVE-2023-51062

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose…

No fix yet
Fix from $1,600 2024-01-13
Rubygems.org CRITICAL 9.8
CVE-2024-21654

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in th…

Fix: 2024-01-08+
Fix from $2,300 2024-01-12
Dgx A100 Firmware HIGH 8.0
CVE-2023-31033

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A…

Fix: 00.22.05+
Fix from $1,950 2024-01-12
H8951 4g Esp Firmware CRITICAL 9.8
CVE-2023-49255

The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration,…

Fix: 2310271149+
Fix from $2,300 2024-01-12
Dir 822 Firmware CRITICAL 9.8
CVE-2023-51987

D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty password…

No fix yet
Fix from $2,300 2024-01-11
Sysmac Cj2h Cpu64 Eip Firmware HIGH 7.5
CVE-2022-45794

An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network protocol to read and write files o…

Mitigation only
Fix from $1,950 2024-01-10
macOS HIGH 7.5
CVE-2023-40393

An authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Photos in the Hid…

Fix: 14.0+
Fix from $1,950 2024-01-10
Windows 10 21h2 MEDIUM 5.7
CVE-2024-21306EPSS 6%

Microsoft Bluetooth Driver Spoofing Vulnerability

Fix: 10.0.19044.3930 / 10.0.19045.3930+
Fix from $1,600 2024-01-09
Jetnet 5310g Firmware CRITICAL 9.1
CVE-2023-5376

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware v…

No fix yet
Fix from $2,300 2024-01-09
Aladdin Connect Garage Door Opener Firmware HIGH 8.2
CVE-2023-5881

Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup…

Fix: after 14.1.1
Fix from $1,950 2024-01-03
Thor CRITICAL 9.8
CVE-2023-29485

An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network …

Fix: after 3.5.3
Fix from $2,300 2023-12-21
Whatsup Gold MEDIUM 5.3
CVE-2023-6368

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthent…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Whatsup Gold MEDIUM 5.3
CVE-2023-6595

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthent…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Repox HIGH 7.5
CVE-2023-6718

An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack …

Mitigation only
Fix from $1,950 2023-12-13
Nautobot MEDIUM 5.3
CVE-2023-50263

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL o…

Fix: 1.6.7 / 2.0.6+
Fix from $1,600 2023-12-12
Poweredge R660 Firmware HIGH 7.8
CVE-2023-32460

Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit thi…

Fix: 1.6.6+
Fix from $1,950 2023-12-08
Prosafe Network Management System CRITICAL 9.8
CVE-2023-49693

NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticate…

Fix: 1.7.0.34+
Fix from $2,300 2023-11-29
Facschorus MEDIUM 5.2
CVE-2023-29061

There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can potentially exploit this vulnerab…

Mitigation only
Fix from $1,600 2023-11-28
Facschorus MEDIUM 5.7
CVE-2023-29060

The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physica…

Mitigation only
Fix from $1,600 2023-11-28