Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Idweb HIGH 7.5
CVE-2023-26571

Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unau…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb CRITICAL 9.1
CVE-2023-26573

Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login cr…

Fix: after 3.1.052
Fix from $2,300 2023-10-25
Idweb HIGH 7.5
CVE-2023-26574

Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by u…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb HIGH 7.5
CVE-2023-26575

Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb HIGH 7.5
CVE-2023-26576

Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student dat…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Idweb MEDIUM 5.3
CVE-2023-26579

Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff information by unauthenticated atta…

Mitigation only
Fix from $1,600 2023-10-25
Idweb HIGH 7.5
CVE-2023-26580

Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthe…

Fix: after 3.1.052
Fix from $1,950 2023-10-25
Sterling Partner Engagement Manager HIGH 7.5
CVE-2023-43045

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authenticat…

Patch available
Fix from $1,950 2023-10-23
Weblogic Server HIGH 8.1
CVE-2023-22101

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Patch available
Fix from $1,950 2023-10-17
Hospitality Opera 5 Property Services HIGH 8.8
CVE-2023-22087

Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version tha…

Patch available
Fix from $1,950 2023-10-17
Weblogic Server CRITICAL 9.8
CVE-2023-22069

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Patch available
Fix from $2,300 2023-10-17
Weblogic Server CRITICAL 9.8
CVE-2023-22072

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1…

Patch available
Fix from $2,300 2023-10-17
Harmonyos CRITICAL 9.8
CVE-2023-44116

Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some …

No fix yet
Fix from $2,300 2023-10-11
A500s Firmware CRITICAL 9.1
CVE-2023-43271

Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp a…

No fix yet
Fix from $2,300 2023-10-09
Open5gs HIGH 7.5
CVE-2023-4884

An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

Fix: after 2.4.10
Fix from $1,950 2023-10-03
Active Directory Integration \/ Ldap Integration MEDIUM 6.5
CVE-2023-4506

The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. Thi…

Fix: after 4.1.10
Fix from $1,600 2023-09-27
Cyber Protect CRITICAL 9.1
CVE-2023-44152

Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linu…

Fix: 15+
Fix from $2,300 2023-09-27
Cilium HIGH 8.1
CVE-2023-41333

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to create or modify CiliumNet…

Fix: 1.12.14 / 1.13.7+
Fix from $1,950 2023-09-27
Junos MEDIUM 5.3
CVE-2023-36851 KEV

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta…

Mitigation only
Fix from $1,600 2023-09-27
Sing Box CRITICAL 9.8
CVE-2023-43644

Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-b…

Fix: 1.4.5+
Fix from $2,300 2023-09-25
Teamcity CRITICAL 9.8
CVE-2023-42793 KEVEPSS 100%

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

Fix: 2023.05.4+
Fix from $2,300 2023-09-19
Digital Yepas CRITICAL 9.8
CVE-2023-4702

Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digit…

Fix: 1.0.1+
Fix from $2,300 2023-09-14
Interactive Graphical Scada System HIGH 7.8
CVE-2023-4516

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change u…

Fix: after 16.0.0.23211
Fix from $1,950 2023-09-14
Netweaver MEDIUM 5.3
CVE-2023-41367

Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain acce…

Mitigation only
Fix from $1,600 2023-09-12
Answer HIGH 8.8
CVE-2023-4815

Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.

Fix: 1.1.3+
Fix from $1,950 2023-09-07
Cacti HIGH 7.8
CVE-2023-31132

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability.…

Fix: 1.2.25+
Fix from $1,950 2023-09-05
Mxsecurity HIGH 7.5
CVE-2023-39981

A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadeq…

Fix: after 1.0.1
Fix from $1,950 2023-09-02
Sel 5037 Sel Grid Configurator HIGH 8.8
CVE-2023-34392

A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an…

Fix: 4.5.0.20+
Fix from $1,950 2023-08-31
Splunk HIGH 8.8
CVE-2023-40598

In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The at…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2023-08-30
Jupyter Server MEDIUM 6.1
CVE-2023-40170

jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain f…

Fix: 2.7.2+
Fix from $1,600 2023-08-28