Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Emui HIGH 7.5
CVE-2022-48494

Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious a…

No fix yet
Fix from $1,950 2023-06-19
Emui HIGH 7.5
CVE-2022-48496

Vulnerability of lax app identity verification in the pre-authorization function.Successful exploitation of this vulnerability will cause malicious a…

No fix yet
Fix from $1,950 2023-06-19
Sick Eventcam App CRITICAL 9.8
CVE-2023-31411

A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of…

Mitigation only
Fix from $2,300 2023-06-19
Cs1w Eip21 Firmware CRITICAL 9.8
CVE-2023-27396

FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks…

Mitigation only
Fix from $2,300 2023-06-19
Kb Ahr04d Firmware CRITICAL 9.8
CVE-2023-30762

Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be …

Fix: 91110.1.101106.78 / 91210.1.101106.78+
Fix from $2,300 2023-06-13
Ac Pd Wapu Firmware HIGH 7.5
CVE-2023-31196

Missing authentication for critical function in Wi-Fi AP UNIT allows a remote unauthenticated attacker to obtain sensitive information of the affecte…

Fix: after 1.05_b04p
Fix from $1,950 2023-06-13
Digital Manufacturing MEDIUM 5.7
CVE-2023-2827

SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of…

Mitigation only
Fix from $1,600 2023-06-13
Megarac Spx CRITICAL 9.1
CVE-2023-34335

AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secure boot pr…

Fix: 12.7 / 13.5+
Fix from $2,300 2023-06-12
Wdrt 1800ax Firmware CRITICAL 9.8
CVE-2023-33553

An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of …

No fix yet
Fix from $2,300 2023-06-07
Scada Data Gateway MEDIUM 5.3
CVE-2023-2187

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.…

Fix: after 5.01.03
Fix from $1,600 2023-06-07
Wordable CRITICAL 9.8
CVE-2020-36724

The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user su…

Fix: after 3.1.1
Fix from $2,300 2023-06-07
Mstore Api CRITICAL 9.8
CVE-2020-36713

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted acces…

Fix: after 2.1.5
Fix from $2,300 2023-06-07
User Email Verification For Woocommerce CRITICAL 9.8
CVE-2023-2781

The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up…

Fix: after 3.5.0
Fix from $2,300 2023-06-03
Chuanhuchatgpt MEDIUM 5.3
CVE-2023-34094

ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 20230526 and prior allows unauth…

Fix: after 2023-05-26
Fix from $1,600 2023-06-02
Powerbpm MEDIUM 5.7
CVE-2023-25780

It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user…

Mitigation only
Fix from $1,600 2023-06-02
Coda 5310 Firmware CRITICAL 9.8
CVE-2023-30604

It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthoriz…

Mitigation only
Fix from $2,300 2023-06-02
Shop Beat Media Player MEDIUM 5.4
CVE-2022-36249

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we…

Fix: 3.2.57+
Fix from $1,600 2023-05-30
Onewireless Network Wireless Device Manager Firmware HIGH 7.5
CVE-2022-4240

Missing Authentication for Critical Function vulnerability in Honeywell OneWireless allows Authentication Bypass. This issue affects OneWireless vers…

Mitigation only
Fix from $1,950 2023-05-30
Data Catalog HIGH 7.5
CVE-2023-33247

Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed …

Fix: 8.0-20230413+
Fix from $1,950 2023-05-26
Emui HIGH 7.5
CVE-2023-31227

The hwPartsDFR module has a vulnerability in API calling verification. Successful exploitation of this vulnerability may affect device confidentialit…

No fix yet
Fix from $1,950 2023-05-26
Emui HIGH 7.5
CVE-2023-0116

The reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect availability.

Mitigation only
Fix from $1,950 2023-05-26
Icip P2012t Firmware HIGH 7.5
CVE-2023-31594

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.

No fix yet
Fix from $1,950 2023-05-25
Hypr Server HIGH 8.8
CVE-2023-1837

Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR…

Fix: 8.0+
Fix from $1,950 2023-05-23
Tr 71w Firmware MEDIUM 5.3
CVE-2023-23545

Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthentic…

Mitigation only
Fix from $1,600 2023-05-23
Bp Social Connect CRITICAL 9.8
CVE-2023-2704

The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient …

Fix: after 1.5
Fix from $2,300 2023-05-19
Metabase CRITICAL 9.6
CVE-2023-32680

Metabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with nat…

Fix: 0.44.7 / 0.45.4+
Fix from $2,300 2023-05-18
Business 140ac Access Point Firmware HIGH 8.8
CVE-2023-20003

A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenti…

Fix: 10.8.1.0+
Fix from $1,950 2023-05-18
Snapcenter CRITICAL 9.8
CVE-2023-1096

SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker …

Mitigation only
Fix from $2,300 2023-05-12
Ue410 En4 Firmware HIGH 8.2
CVE-2023-23444

Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 10440…

Mitigation only
Fix from $1,950 2023-05-12
Skybridge Mb A110 Firmware HIGH 7.5
CVE-2023-23906

Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticate…

Fix: after 4.2.0
Fix from $1,950 2023-05-10