Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Clearpass Policy Manager CRITICAL 9.8
CVE-2023-25589

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary …

Fix: after 6.10.8
Fix from $2,300 2023-03-22
Custom Reports MEDIUM 5.3
CVE-2023-27983

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports fr…

Fix: after 16.0.0.23040
Fix from $1,600 2023-03-21
Custom Reports HIGH 8.8
CVE-2023-27980

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a mali…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Arrayos Ag CRITICAL 9.8
CVE-2023-28461 KEVEPSS 68%

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gat…

Fix: after 9.4.0.481
Fix from $2,300 2023-03-15
Netweaver Application Server Java MEDIUM 5.3
CVE-2023-24526

SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that requi…

No fix yet
Fix from $1,600 2023-03-14
Veeam Backup \& Replication HIGH 7.5
CVE-2023-27532 KEVEPSS 78%

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead…

Fix: 11.0.1.1261+
Fix from $1,950 2023-03-10
Observability With Instana CRITICAL 9.1
CVE-2023-27290EPSS 9%

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require…

Fix: after 241-2
Fix from $2,300 2023-03-03
We1626 Firmware CRITICAL 9.8
CVE-2022-45551EPSS 23%

An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Net…

Mitigation only
Fix from $2,300 2023-03-03
Workspace One Content MEDIUM 6.8
CVE-2023-20857

VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with access to a users rooted device, may be able to bypass…

Fix: 23.02+
Fix from $1,600 2023-02-28
751 9301 Firmware CRITICAL 9.8
CVE-2022-45138

The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use t…

Fix: 22+
Fix from $2,300 2023-02-27
751 9301 Firmware CRITICAL 9.8
CVE-2022-45140

The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthentic…

Fix: 22+
Fix from $2,300 2023-02-27
Aremis 4 Nomads HIGH 7.5
CVE-2022-34908

An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features d…

Fix: 1.5.1+
Fix from $1,950 2023-02-27
Fx0 Gpnt00000 Firmware CRITICAL 9.8
CVE-2023-23452

Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve a…

Mitigation only
Fix from $2,300 2023-02-20
Fx0 Gent00010 Firmware CRITICAL 9.8
CVE-2023-23453

Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve a…

Mitigation only
Fix from $2,300 2023-02-20
Gnuboard HIGH 7.5
CVE-2022-44216

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original passwo…

Patch available
Fix from $1,950 2023-02-20
Apollo HIGH 7.5
CVE-2023-25570

Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the …

Fix: 2.1.0+
Fix from $1,950 2023-02-20
Online Pizza Ordering System CRITICAL 9.8
CVE-2023-0906

A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vulnerability is the function d…

Mitigation only
Fix from $2,300 2023-02-18
Cpe906 3 HIGH 7.5
CVE-2022-47703

TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware Version MV8.003, and Hardwar…

No fix yet
Fix from $1,950 2023-02-16
Gotham MEDIUM 5.3
CVE-2022-27891

Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have…

Fix: 3.22.10.4+
Fix from $1,600 2023-02-16
Xbc Dn32u Firmware CRITICAL 9.1
CVE-2023-0102

LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete …

Mitigation only
Fix from $2,300 2023-02-15
Xbc Dn32u Firmware HIGH 7.5
CVE-2023-22803

LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC. This could allow an att…

Mitigation only
Fix from $1,950 2023-02-15
Xbc Dn32u Firmware CRITICAL 9.8
CVE-2023-22804

LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to creat…

Mitigation only
Fix from $2,300 2023-02-15
Emui HIGH 7.5
CVE-2022-48300

The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

No fix yet
Fix from $1,950 2023-02-09
Emui HIGH 7.5
CVE-2022-48299

The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

No fix yet
Fix from $1,950 2023-02-09
Emui HIGH 7.5
CVE-2022-48288

The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data …

Mitigation only
Fix from $1,950 2023-02-09
Emui HIGH 7.5
CVE-2022-48289

The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data …

No fix yet
Fix from $1,950 2023-02-09
Industrial Automation Aprol HIGH 7.5
CVE-2022-43761

Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configurati…

Mitigation only
Fix from $1,950 2023-02-08
Rn4870 Firmware MEDIUM 5.3
CVE-2022-45190

An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in the legacy pairing of the de…

Mitigation only
Fix from $1,600 2023-02-08
Terramaster Operating System HIGH 7.5
CVE-2022-24990 KEVEPSS 83%

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mo…

Fix: 4.2.31+
Fix from $1,950 2023-02-07
Unified Remote CRITICAL 9.8
CVE-2022-3229EPSS 66%

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated a…

Fix: after 3.11.0.2483
Fix from $2,300 2023-02-06