Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Modern Honey Network MEDIUM 6.5
CVE-2021-37234

Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensit…

Fix: 2021-10-30+
Fix from $1,600 2023-02-03
Femanager HIGH 7.5
CVE-2023-25013

An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit…

Fix: 5.5.3 / 6.3.4+
Fix from $1,950 2023-02-02
Femanager HIGH 7.5
CVE-2023-25014

An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit…

Fix: 5.5.3 / 6.3.4+
Fix from $1,950 2023-02-02
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2022-42970

A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable u…

Fix: 2.5-ga / 2.5-gs+
Fix from $2,300 2023-02-01
Interactive Graphical Scada System CRITICAL 9.1
CVE-2022-32528

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGS…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Server HIGH 7.5
CVE-2021-43447

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to…

Fix: after 7.0.0.49
Fix from $1,950 2023-01-23
Tapo C200 V1 Firmware MEDIUM 6.4
CVE-2022-41505

An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UART pins, i…

No fix yet
Fix from $1,600 2023-01-23
Nova 220 Eyk220f001 Firmware HIGH 8.8
CVE-2023-0052

SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands w…

Fix: after 3.3-006
Fix from $1,950 2023-01-20
R310 Firmware MEDIUM 6.5
CVE-2020-22661

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10…

Fix: 3.6.2.0.795+
Fix from $1,600 2023-01-20
Electerm CRITICAL 9.8
CVE-2020-23256

An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electerms service.

Patch available
Fix from $2,300 2023-01-20
Pfc100 Firmware MEDIUM 5.9
CVE-2022-3738

The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive informa…

Fix: after 22
Fix from $1,600 2023-01-19
Isetup HIGH 7.5
CVE-2023-21856

Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that…

Fix: after 12.2.12
Fix from $1,950 2023-01-18
Weblogic Server HIGH 7.5
CVE-2023-21837

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Patch available
Fix from $1,950 2023-01-18
Weblogic Server HIGH 7.5
CVE-2023-21839 KEVEPSS 100%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Patch available
Fix from $1,950 2023-01-18
Weblogic Server HIGH 7.5
CVE-2023-21842

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are…

Patch available
Fix from $1,950 2023-01-18
Proficy Historian CRITICAL 9.8
CVE-2022-46732

Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.

Fix: 2023+
Fix from $2,300 2023-01-18
Ms 3000 Firmware CRITICAL 9.8
CVE-2022-43976

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possibl…

Fix: 3.7.6.25p0_3.2.2.17p0_4.7p0+
Fix from $2,300 2023-01-17
Dgx A100 Firmware HIGH 8.2
CVE-2022-42276

NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which…

Fix: 1.18+
Fix from $1,950 2023-01-13
Dgx Station A100 Firmware HIGH 8.2
CVE-2022-42277

NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, wh…

Fix: 10.16+
Fix from $1,950 2023-01-13
Bmc HIGH 7.1
CVE-2022-42275

NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of inte…

Fix: 00.19.07+
Fix from $1,950 2023-01-13
Harbor HIGH 7.5
CVE-2022-46463EPSS 6%

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the…

Fix: after 2.5.3
Fix from $1,950 2023-01-13
Sharepoint Server MEDIUM 5.3
CVE-2023-21743

Microsoft SharePoint Server Security Feature Bypass Vulnerability

No fix yet
Fix from $1,600 2023-01-10
Dss Express HIGH 7.5
CVE-2022-45423

Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials b…

Patch available
Fix from $1,950 2022-12-27
Dss Express MEDIUM 5.3
CVE-2022-45424

Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending …

Patch available
Fix from $1,600 2022-12-27
Dhi Dss7016d S2 Firmware MEDIUM 5.3
CVE-2022-45432

Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sendi…

Patch available
Fix from $1,600 2022-12-27
Lieferantenmanager CRITICAL 9.1
CVE-2022-44013

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because the password …

Fix: 5.6+
Fix from $2,300 2022-12-25
Iboot Pdu4 N20 Firmware MEDIUM 5.3
CVE-2022-3188

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authent…

Fix: 1.42.06162022+
Fix from $1,600 2022-12-21
Sim2000 Firmware CRITICAL 9.8
CVE-2022-47377

Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain acc…

Fix: 1.13.4+
Fix from $2,300 2022-12-16
Access MEDIUM 5.3
CVE-2022-31701

VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be…

Mitigation only
Fix from $1,600 2022-12-14
Netweaver Process Integration HIGH 8.6
CVE-2022-41272

An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver P…

Mitigation only
Fix from $1,950 2022-12-13