Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
A1 Firmware HIGH 7.5
CVE-2023-3104

Lack of authentication vulnerability. An unauthenticated local user is able to see through the cameras using the web server due to the lack of any fo…

Mitigation only
Fix from $1,950 2023-11-22
St Ipm 6350 Firmware CRITICAL 9.8
CVE-2023-42770

Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over…

Patch available
Fix from $2,300 2023-11-21
Cfr 1004ea Firmware CRITICAL 9.8
CVE-2023-47674

Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain …

Mitigation only
Fix from $2,300 2023-11-16
Cloud Director CRITICAL 9.8
CVE-2023-34060

VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an …

Fix: 10.5+
Fix from $2,300 2023-11-14
Simatic Pcs Neo MEDIUM 6.5
CVE-2023-46096

A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly authenticate use…

Fix: 4.1+
Fix from $1,600 2023-11-14
Ofbiz MEDIUM 5.3
CVE-2023-46819

Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin. This issue affects Apache OFBiz: before 18.12.09.  Use…

Fix: 18.12.09+
Fix from $1,600 2023-11-07
Fx3u 32mt\/es Firmware CRITICAL 9.1
CVE-2023-4699

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC-F Series CPU modules, MELSEC iQ-F Series, MELSEC…

Mitigation only
Fix from $2,300 2023-11-06
Linx 212 Firmware HIGH 8.2
CVE-2023-46381EPSS 7%

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the prei…

No fix yet
Fix from $1,950 2023-11-04
Avalanche HIGH 7.8
CVE-2022-43554

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
Avalanche HIGH 7.8
CVE-2022-43555

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41351

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentic…

Mitigation only
Fix from $2,300 2023-11-03
Authentik CRITICAL 9.8
CVE-2023-46249

authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentia…

Fix: 2023.8.4 / 2023.10.2+
Fix from $2,300 2023-10-31
X6000r Firmware HIGH 7.5
CVE-2023-46978

TOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords without authenti…

No fix yet
Fix from $1,950 2023-10-31
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2023-46747 KEVEPSS 97%

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manag…

Fix: after 17.1.1
Fix from $2,300 2023-10-26
Ipados MEDIUM 5.3
CVE-2023-42845

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. Photos in t…

Fix: 14.1 / 17.1+
Fix from $1,600 2023-10-25
macOS HIGH 7.5
CVE-2023-40401

The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may be able to access passkeys w…

Fix: 13.6.1+
Fix from $1,950 2023-10-25
Ctrlx Hmi Web Panel Wr2107 Firmware HIGH 8.8
CVE-2023-45851

The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  This…

Mitigation only
Fix from $1,950 2023-10-25
Ctrlx Hmi Web Panel Wr2107 Firmware HIGH 8.8
CVE-2023-45220

The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retriev…

Mitigation only
Fix from $1,950 2023-10-25
Ctrlx Hmi Web Panel Wr2107 Firmware HIGH 8.8
CVE-2023-41255

The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the …

Mitigation only
Fix from $1,950 2023-10-25
Pingone Mfa Integration Kit MEDIUM 6.5
CVE-2023-39231

PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authentication from an existing regis…

Mitigation only
Fix from $1,600 2023-10-25
Pingid Radius Pcv CRITICAL 9.8
CVE-2023-39930

A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via…

Fix: 3.0.3+
Fix from $2,300 2023-10-25
Idweb MEDIUM 5.3
CVE-2023-27256

Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by una…

Fix: after 3.1.052
Fix from $1,600 2023-10-25
Idweb HIGH 7.5
CVE-2023-27257

Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student informa…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb HIGH 7.5
CVE-2023-27258

Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and …

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb HIGH 7.5
CVE-2023-27259

Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive studen…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb MEDIUM 6.5
CVE-2023-27261

Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthe…

Fix: after 3.1.052
Fix from $1,600 2023-10-25
Idweb HIGH 7.5
CVE-2023-27375

Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction o…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb HIGH 7.5
CVE-2023-27376

Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction o…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb HIGH 7.5
CVE-2023-27377

Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows ex…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb HIGH 7.5
CVE-2023-26570

Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive st…

Fix: after 3.1.052
Fix from $1,950 2023-10-25