Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Infrasuite Device Master CRITICAL 9.1
CVE-2022-41629

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could all…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Infrasuite Device Master HIGH 8.8
CVE-2022-41644

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacke…

Fix: 00.00.02a+
Fix from $1,950 2022-10-31
Infrasuite Device Master HIGH 7.5
CVE-2022-41688

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. …

Fix: 00.00.02a+
Fix from $1,950 2022-10-31
Infrasuite Device Master HIGH 7.5
CVE-2022-41776

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which c…

Fix: 00.00.02a+
Fix from $1,950 2022-10-31
Infrasuite Device Master CRITICAL 9.8
CVE-2022-40202

The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker coul…

Fix: 00.00.02a+
Fix from $2,300 2022-10-31
Haas Controller Firmware HIGH 8.0
CVE-2022-2474

Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any use…

Mitigation only
Fix from $1,950 2022-10-28
Sanitization Management System CRITICAL 9.8
CVE-2022-3674

A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an …

Mitigation only
Fix from $2,300 2022-10-26
Free5gc HIGH 7.5
CVE-2022-38870

Free5gc v3.2.1 is vulnerable to Information disclosure.

No fix yet
Fix from $1,950 2022-10-25
Diskstation Manager CRITICAL 9.1
CVE-2022-27623

Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 a…

Fix: 7.1-42661+
Fix from $2,300 2022-10-25
Tug Home Base Server HIGH 8.1
CVE-2022-1070

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Fix: 24+
Fix from $1,950 2022-10-21
Rdiffweb CRITICAL 9.8
CVE-2022-3327

Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.

Fix: 2.4.10+
Fix from $2,300 2022-10-20
Rt N12e Firmware HIGH 7.5
CVE-2020-23648

Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the admi…

No fix yet
Fix from $1,950 2022-10-19
Access Manager HIGH 7.5
CVE-2022-39412

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affected is …

Patch available
Fix from $1,950 2022-10-18
Vm Virtualbox HIGH 8.1
CVE-2022-39425

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4…

Fix: 6.1.40+
Fix from $1,950 2022-10-18
Vm Virtualbox HIGH 8.1
CVE-2022-39426

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4…

Fix: 6.1.40+
Fix from $1,950 2022-10-18
E Business Suite CRITICAL 9.8
CVE-2022-21587 KEVEPSS 98%

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are a…

Fix: after 12.2.11
Fix from $2,300 2022-10-18
Iot Platform MEDIUM 6.5
CVE-2022-35136

Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.

No fix yet
Fix from $1,600 2022-10-13
Catalyst Sd Wan Manager MEDIUM 5.3
CVE-2022-20830

A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an una…

Fix: 20.3.4.1 / 20.6.1+
Fix from $1,600 2022-10-10
Dapr Dashboard HIGH 7.5
CVE-2022-38817

Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

Fix: after 0.10.0
Fix from $1,950 2022-10-03
Cpy Car Park Server CRITICAL 9.8
CVE-2022-22526

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.

Fix: 2.8.3 / 8.5.0.3+
Fix from $2,300 2022-09-28
Crystal Quality MEDIUM 5.3
CVE-2022-36780

Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authentica…

No fix yet
Fix from $1,600 2022-09-13
E5350 Firmware HIGH 7.5
CVE-2022-35572

On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm …

Fix: after 1.0.00.037
Fix from $1,950 2022-09-12
Spectrum Wireless Battery Module Firmware MEDIUM 5.4
CVE-2022-26394

The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middl…

Fix: after 20d32
Fix from $1,600 2022-09-09
3d A1000 Dimensioning System Firmware CRITICAL 9.8
CVE-2022-1368

The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Func…

Fix: after 1.0.3
Fix from $2,300 2022-09-06
Grafana Image Renderer HIGH 8.1
CVE-2022-31176

Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). …

Fix: 3.6.1+
Fix from $1,950 2022-09-02
Avalon Asic Miner Firmware HIGH 7.5
CVE-2022-36604

An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a c…

Fix: after 2020.3.30
Fix from $1,950 2022-09-01
Dir 816 Firmware HIGH 7.5
CVE-2022-36619

In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.

No fix yet
Fix from $1,950 2022-08-31
Experion Lx Firmware CRITICAL 9.1
CVE-2022-30317

Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experi…

Mitigation only
Fix from $2,300 2022-08-31
Hc Ip9100hd Firmware HIGH 7.5
CVE-2022-37680

An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring system (Camera, Decoder and Encode…

Fix: after 1.07
Fix from $1,950 2022-08-29
Cskefu HIGH 7.5
CVE-2022-36521

Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.

No fix yet
Fix from $1,950 2022-08-26