Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Udr Ja1004 Firmware CRITICAL 9.8
CVE-2022-35733

Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1…

Fix: after 2.0.20.13
Fix from $2,300 2022-08-23
Oauth 2.0 Client For Sso CRITICAL 9.8
CVE-2022-34858

Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.

Fix: 1.11.4+
Fix from $2,300 2022-08-22
Duplicator MEDIUM 5.3
CVE-2022-2552EPSS 11%

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…

Fix: 1.4.7.1+
Fix from $1,600 2022-08-22
Flir Ax8 Firmware HIGH 7.5
CVE-2022-37062

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory…

Fix: after 1.46.16
Fix from $1,950 2022-08-18
Gw1100 Firmware CRITICAL 9.1
CVE-2022-35122

An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information i…

Fix: after 2.1.5
Fix from $2,300 2022-08-17
Company Website Cms CRITICAL 9.8
CVE-2022-2765

A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown f…

No fix yet
Fix from $2,300 2022-08-11
Systemsoftware V\/kss CRITICAL 9.8
CVE-2022-2242

The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write …

Fix: 8.6.5+
Fix from $2,300 2022-08-10
Track It\! CRITICAL 9.8
CVE-2022-35865

This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re…

Patch available
Fix from $2,300 2022-08-03
Safety Manager Firmware HIGH 7.5
CVE-2022-30313

Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a …

Mitigation only
Fix from $1,950 2022-07-28
Git MEDIUM 5.3
CVE-2022-36884

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to…

Fix: after 4.11.3
Fix from $1,600 2022-07-27
Moscad Ip Gateway Firmware HIGH 7.5
CVE-2022-30276

The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for inter…

Mitigation only
Fix from $1,950 2022-07-26
Vault CRITICAL 9.1
CVE-2022-36129

HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that coul…

Fix: after 1.10.4
Fix from $2,300 2022-07-26
Pc10g Cpu Tcc 6353 Firmware CRITICAL 9.1
CVE-2022-29951

JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP…

Mitigation only
Fix from $2,300 2022-07-26
Bently Nevada 3701\/40 Firmware CRITICAL 9.1
CVE-2022-29952

Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP,…

Fix: 4.1+
Fix from $2,300 2022-07-26
Deltav Distributed Control System HIGH 7.8
CVE-2022-29957

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wid…

Fix: after 2022-04-29
Fix from $1,950 2022-07-26
Ignition HIGH 7.8
CVE-2022-35871EPSS 39%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…

Mitigation only
Fix from $1,950 2022-07-25
Iview HIGH 7.5
CVE-2022-2138EPSS 11%

The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary …

Fix: 5.7.04.6469+
Fix from $1,950 2022-07-22
Metasys Application And Data Server MEDIUM 5.3
CVE-2021-36200

Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions …

Fix: 10.1.6 / 11.0.2+
Fix from $1,600 2022-07-22
All Wr0500ac Firmware CRITICAL 9.8
CVE-2022-34767

Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows …

Mitigation only
Fix from $2,300 2022-07-21
Nexus Dashboard CRITICAL 9.8
CVE-2022-20857

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…

Fix: 2.2+
Fix from $2,300 2022-07-21
Nexus Dashboard CRITICAL 9.8
CVE-2022-20858

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…

Fix: 2.2+
Fix from $2,300 2022-07-21
Nexus Dashboard HIGH 8.8
CVE-2022-20861

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…

Fix: 2.2+
Fix from $1,950 2022-07-21
Mv720 Firmware CRITICAL 9.8
CVE-2022-2141

SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.

Mitigation only
Fix from $2,300 2022-07-20
Drawings Sdk HIGH 7.8
CVE-2022-28809

An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with a…

Fix: 2023.3+
Fix from $1,950 2022-07-17
Resourcespace MEDIUM 6.5
CVE-2022-31260

In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k v…

Fix: 9.8+
Fix from $1,600 2022-07-17
Hive HIGH 7.5
CVE-2021-34538

Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was…

Fix: 3.1.3+
Fix from $1,950 2022-07-16
Business One License Service Api HIGH 7.5
CVE-2022-28771

Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http re…

Mitigation only
Fix from $1,950 2022-07-12
Simatic Easie Core Package CRITICAL 9.1
CVE-2021-44222

A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not p…

Fix: 22.00+
Fix from $2,300 2022-07-12
Simatic Mv540 H Firmware HIGH 7.5
CVE-2022-33138

A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < …

Fix: 3.3+
Fix from $1,950 2022-07-12
Pingid Integration For Windows Login MEDIUM 6.4
CVE-2022-23719

PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker wi…

Fix: 2.8+
Fix from $1,600 2022-06-30