Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Skybridge Basic Mb A130 Firmware HIGH 8.6
CVE-2023-22441

Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the set…

Fix: after 1.4.1
Fix from $1,950 2023-05-10
Mage Ai CRITICAL 9.8
CVE-2023-31143

mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72…

Fix: 0.8.72+
Fix from $2,300 2023-05-09
Netweaver Application Server For Java CRITICAL 9.1
CVE-2023-30744

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and…

Mitigation only
Fix from $2,300 2023-05-09
Spa112 Firmware CRITICAL 9.8
CVE-2023-20126EPSS 37%

A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execut…

Mitigation only
Fix from $2,300 2023-05-04
Studio HIGH 7.5
CVE-2023-31444

In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the micro…

Fix: 7.3.1-r2022-10 / 8.0.1-r2022-09+
Fix from $1,950 2023-04-28
Miineport E1 Firmware CRITICAL 9.8
CVE-2023-28697

Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitr…

Mitigation only
Fix from $2,300 2023-04-27
Desktop MEDIUM 6.1
CVE-2022-40725

PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted…

Fix: 1.7.4+
Fix from $1,600 2023-04-25
Max G866ac Firmware CRITICAL 9.8
CVE-2023-2231

A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component…

Mitigation only
Fix from $2,300 2023-04-21
Ue410 En3 Firmware CRITICAL 9.8
CVE-2023-23451

The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FL…

Fix: after 2.12.0
Fix from $2,300 2023-04-19
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2023-29411

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to poten…

Fix: after 2.5-gs-01-22320
Fix from $2,300 2023-04-18
Apc Easy Ups Online Monitoring Software HIGH 7.5
CVE-2023-29413

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated u…

Fix: after 2.5-gs-01-22320
Fix from $1,950 2023-04-18
Weblogic Server HIGH 7.5
CVE-2023-21979

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Mitigation only
Fix from $1,950 2023-04-18
Weblogic Server HIGH 7.5
CVE-2023-21931EPSS 82%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Patch available
Fix from $1,950 2023-04-18
Dg3450 Firmware MEDIUM 5.3
CVE-2023-27571

An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionali…

No fix yet
Fix from $1,600 2023-04-15
Malware Protection Platform MEDIUM 5.5
CVE-2023-24934

Microsoft Defender Security Feature Bypass Vulnerability

Fix: 4.18.2303.8+
Fix from $1,600 2023-04-14
Dr750 2ch Lte Firmware HIGH 7.5
CVE-2023-27747

BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive i…

No fix yet
Fix from $1,950 2023-04-13
Fortiproxy CRITICAL 9.8
CVE-2022-41331

A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, u…

Fix: 2.0.0+
Fix from $2,300 2023-04-11
Netweaver As Java For Deploy Service MEDIUM 5.3
CVE-2023-24527

SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity ena…

Mitigation only
Fix from $1,600 2023-04-11
Diagnostics Agent HIGH 8.1
CVE-2023-27267EPSS 14%

Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with…

Mitigation only
Fix from $1,950 2023-04-11
Diagnostics Agent CRITICAL 9.8
CVE-2023-27497

Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker …

Mitigation only
Fix from $2,300 2023-04-11
Netweaver Enterprise Portal MEDIUM 6.5
CVE-2023-28761

In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access …

Mitigation only
Fix from $1,600 2023-04-11
Xiaomi Router Firmware HIGH 7.5
CVE-2020-14140

When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is ca…

Fix: 2023.2+
Fix from $1,950 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36983

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to …

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Lax20 Firmware HIGH 8.8
CVE-2022-27645

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is…

Fix: 1.0.4.84 / 1.0.4.126+
Fix from $1,950 2023-03-29
Openmeetings CRITICAL 9.8
CVE-2023-28326

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privi…

Fix: 7.0.0+
Fix from $2,300 2023-03-28
Emui MEDIUM 6.5
CVE-2022-48291

The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect conf…

No fix yet
Fix from $1,600 2023-03-27
Infrasuite Device Master CRITICAL 9.8
CVE-2023-1140

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated re…

Fix: 1.0.5+
Fix from $2,300 2023-03-27
Powerstation Firmware CRITICAL 9.8
CVE-2023-24838

HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini…

Mitigation only
Fix from $2,300 2023-03-27
Couchbase Server MEDIUM 5.3
CVE-2023-28470

In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.

Fix: 7.1.4+
Fix from $1,600 2023-03-23
Lightcms CRITICAL 9.8
CVE-2023-27060

LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.

Patch available
Fix from $2,300 2023-03-22