Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Adm 100 Firmware HIGH 7.5
CVE-2023-38030

Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attac…

Mitigation only
Fix from $1,950 2023-08-28
Adm 100 Firmware CRITICAL 9.1
CVE-2023-38028

Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to…

Mitigation only
Fix from $2,300 2023-08-28
Ironic Image HIGH 7.5
CVE-2023-40585

ironic-image is a container image to run OpenStack Ironic as part of Metal³. Prior to version capm3-v1.4.3, if Ironic is not deployed with TLS and it…

Fix: 1.4.3+
Fix from $1,950 2023-08-25
Intuition 9 Firmware HIGH 7.5
CVE-2023-38422

Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the management web server. This could a…

Fix: 4.21+
Fix from $1,950 2023-08-23
Junos MEDIUM 5.3
CVE-2023-36846 KEVEPSS 95%

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta…

Fix: 20.4+
Fix from $1,600 2023-08-17
Junos MEDIUM 5.3
CVE-2023-36847 KEVEPSS 86%

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attac…

Fix: 20.4+
Fix from $1,600 2023-08-17
Raid Controller Web Interface HIGH 7.5
CVE-2023-4334

Broadcom RAID Controller Web server (nginx) is serving private files without any authentication

Mitigation only
Fix from $1,950 2023-08-15
Raid Controller Web Interface HIGH 7.5
CVE-2023-4335

Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux

Mitigation only
Fix from $1,950 2023-08-15
Emui HIGH 7.5
CVE-2023-39380

Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

No fix yet
Fix from $1,950 2023-08-13
Windows 10 21h2 CRITICAL 9.8
CVE-2023-38186

Windows Mobile Device Management Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2023-08-08
Ruggedcom Crossbow HIGH 7.5
CVE-2023-37373

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file write messages…

Fix: 5.4+
Fix from $1,950 2023-08-08
Supplier Relationship Management MEDIUM 5.8
CVE-2023-39436

SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relati…

Mitigation only
Fix from $1,600 2023-08-08
Host Agent MEDIUM 5.3
CVE-2023-36926

Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular c…

Mitigation only
Fix from $1,600 2023-08-08
Powerdesigner CRITICAL 9.8
CVE-2023-37483

SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back…

Mitigation only
Fix from $2,300 2023-08-08
Fgn1115 Wp Wh Firmware MEDIUM 5.3
CVE-2023-38523

The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, without authentication, exposing …

Fix: 1.15.61+
Fix from $1,600 2023-07-20
Peoplesoft Enterprise HIGH 7.5
CVE-2023-22047EPSS 77%

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.…

Patch available
Fix from $1,950 2023-07-18
Megarac Sp X HIGH 8.0
CVE-2023-34329

AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit o…

Mitigation only
Fix from $1,950 2023-07-18
Ngc Indoor Unit Firmware CRITICAL 9.8
CVE-2023-36669

Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary contro…

Fix: 11.4+
Fix from $2,300 2023-07-18
Casaos CRITICAL 9.8
CVE-2023-37265EPSS 7%

CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands …

Fix: 0.4.4+
Fix from $2,300 2023-07-17
Mso5000 Firmware HIGH 7.5
CVE-2023-38379

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a z…

No fix yet
Fix from $1,950 2023-07-16
Netweaver Application Server Abap HIGH 7.4
CVE-2023-35874

SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53,…

Mitigation only
Fix from $1,950 2023-07-11
Netweaver Process Integration MEDIUM 6.5
CVE-2023-35872

The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain funct…

Mitigation only
Fix from $1,600 2023-07-11
Netweaver Process Integration MEDIUM 6.5
CVE-2023-35873

The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functi…

Mitigation only
Fix from $1,600 2023-07-11
Android HIGH 7.1
CVE-2023-30643

Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloade…

Mitigation only
Fix from $1,950 2023-07-06
Qubo Hcd01 Firmware HIGH 8.8
CVE-2023-22906

Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.

No fix yet
Fix from $1,950 2023-07-04
Codekop HIGH 7.5
CVE-2023-36347EPSS 34%

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

No fix yet
Fix from $1,950 2023-06-30
Bookit CRITICAL 9.8
CVE-2023-2834

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verificat…

Fix: after 2.3.7
Fix from $2,300 2023-06-30
Tcg 4 Firmware CRITICAL 9.8
CVE-2023-35830

STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite C…

Mitigation only
Fix from $2,300 2023-06-29
Hello Cup MEDIUM 6.5
CVE-2023-34761

An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the appl…

No fix yet
Fix from $1,600 2023-06-28
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2023-35854EPSS 6%

Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for…

Fix: 6.1+
Fix from $2,300 2023-06-20