Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Netweaver Process Integration CRITICAL 9.4
CVE-2022-41271

An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - vers…

Mitigation only
Fix from $2,300 2022-12-13
W6 S Firmware HIGH 7.5
CVE-2022-45498

An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily r…

No fix yet
Fix from $1,950 2022-12-08
W6 S Firmware HIGH 7.5
CVE-2022-45504EPSS 18%

An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrari…

No fix yet
Fix from $1,950 2022-12-08
Pc Keyboard Wifi\&bluetooth CRITICAL 9.8
CVE-2022-45479

PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or au…

Fix: after 30
Fix from $2,300 2022-12-05
Lazy Mouse CRITICAL 9.8
CVE-2022-45481

The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior au…

Fix: after 2.0.1
Fix from $2,300 2022-12-05
Telepad CRITICAL 9.8
CVE-2022-45477

Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authen…

Fix: after 1.0.7
Fix from $2,300 2022-12-05
Access Appliance CRITICAL 9.8
CVE-2022-46414

An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution ca…

Fix: after 8.0.100
Fix from $2,300 2022-12-04
Authentik CRITICAL 9.8
CVE-2022-46145

authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential a…

Fix: 2022.10.2 / 2022.11.2+
Fix from $2,300 2022-12-02
Book Store Management System HIGH 7.5
CVE-2022-4228

A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affects an unknown part of the file…

No fix yet
Fix from $1,950 2022-11-30
Book Store Management System CRITICAL 9.8
CVE-2022-4229

A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability affects unknown code of the f…

No fix yet
Fix from $2,300 2022-11-30
Ourphoto HIGH 7.5
CVE-2022-24190

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implem…

No fix yet
Fix from $1,950 2022-11-28
Kubeview CRITICAL 9.8
CVE-2022-45933EPSS 52%

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, an…

Fix: after 0.1.31
Fix from $2,300 2022-11-27
Appalti \& Contratti HIGH 8.8
CVE-2022-44784

An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the Axis 1.4 in…

No fix yet
Fix from $1,950 2022-11-21
Backclick CRITICAL 9.8
CVE-2022-44001

An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.

No fix yet
Fix from $2,300 2022-11-17
Bkg Professional Ntripcaster HIGH 7.5
CVE-2022-42982

BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quit…

Fix: after 2.0.39
Fix from $1,950 2022-11-17
Backclick CRITICAL 9.8
CVE-2022-44000

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary sy…

No fix yet
Fix from $2,300 2022-11-16
Backclick CRITICAL 9.8
CVE-2022-43999

An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the …

No fix yet
Fix from $2,300 2022-11-16
At Modem Emulator Firmware CRITICAL 9.8
CVE-2022-42785

Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge …

Fix: 1.48 / 1.76+
Fix from $2,300 2022-11-15
Soap CRITICAL 9.8
CVE-2022-45378

In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invok…

Fix: after 2.3
Fix from $2,300 2022-11-14
Emui HIGH 7.5
CVE-2021-46852

The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

No fix yet
Fix from $1,950 2022-11-09
Biotime MEDIUM 5.3
CVE-2022-30515

ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.

No fix yet
Fix from $1,600 2022-11-08
Scopia Pathfinder 10 Pts Firmware CRITICAL 9.1
CVE-2022-38168

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to by…

No fix yet
Fix from $2,300 2022-11-03
Fedora Coreos MEDIUM 5.5
CVE-2022-3675

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the…

Fix: 37.20221031.1.0+
Fix from $1,600 2022-11-03
Fortisoar MEDIUM 5.5
CVE-2022-42473

A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to …

Fix: after 7.0.3
Fix from $1,600 2022-11-02
Sim1012 0p0g200 Firmware HIGH 7.3
CVE-2022-43990

Password recovery vulnerability in SICK SIM1012 Partnumber 1098146 with firmware version <2.2.0 allows an unprivileged remote attacker to gain access…

Fix: 2.2.0+
Fix from $1,950 2022-11-01
Sim2000 Firmware CRITICAL 9.8
CVE-2022-27582

Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defin…

Fix: 1.2.0 / 1.6.0+
Fix from $2,300 2022-11-01
Sim2000st Firmware CRITICAL 9.8
CVE-2022-27584

Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel defined a…

Mitigation only
Fix from $2,300 2022-11-01
Sim1000 Fx Firmware CRITICAL 9.8
CVE-2022-27585

Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote attacker…

Fix: 1.6.0+
Fix from $2,300 2022-11-01
Sim1004 0p0g311 Firmware CRITICAL 9.8
CVE-2022-27586

Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access…

Fix: 2.0.0+
Fix from $2,300 2022-11-01
Sim2000 2p04g10 Firmware HIGH 7.3
CVE-2022-43989

Password recovery vulnerability in SICK SIM2x00 (ARM) Partnumber 1092673 and 1081902 with firmware version < 1.2.0 allows an unprivileged remote atta…

Fix: 1.2.0+
Fix from $1,950 2022-11-01