Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Local Run Manager CRITICAL 9.1
CVE-2022-1521

LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.

Fix: after 3.1
Fix from $2,300 2022-06-24
Sihas Sgw 300 Firmware CRITICAL 9.8
CVE-2021-26637

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized…

Mitigation only
Fix from $2,300 2022-06-23
Manager Server HIGH 7.5
CVE-2022-21952

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote atta…

Fix: 4.1.46 / 4.2.37+
Fix from $1,950 2022-06-22
Iotransfer CRITICAL 9.8
CVE-2022-24562EPSS 53%

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the ent…

Mitigation only
Fix from $2,300 2022-06-16
Ariang CRITICAL 9.8
CVE-2021-41418

AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.

Fix: after 1.2.2
Fix from $2,300 2022-06-15
Splunk HIGH 7.5
CVE-2022-32157

Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to updat…

Fix: 9.0+
Fix from $1,950 2022-06-15
Couchbase Server HIGH 7.5
CVE-2022-32557

An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.

Fix: 7.0.4+
Fix from $1,950 2022-06-14
Sicam Gridedge Essential HIGH 7.2
CVE-2022-30229

A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated acce…

Fix: 2.6.6+
Fix from $1,950 2022-06-14
Sicam Gridedge Essential CRITICAL 9.8
CVE-2022-30230

A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated acce…

Fix: 2.6.6+
Fix from $2,300 2022-06-14
Sinema Remote Connect Server CRITICAL 9.8
CVE-2022-32251

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resou…

Fix: 3.1+
Fix from $2,300 2022-06-14
Envoy CRITICAL 9.1
CVE-2022-29226

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validati…

Fix: 1.22.1+
Fix from $2,300 2022-06-09
Wpqa Builder MEDIUM 5.3
CVE-2022-1598EPSS 5%

The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unau…

Fix: 5.4+
Fix from $1,600 2022-06-08
Ex1200t Firmware HIGH 7.5
CVE-2021-42893

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.

No fix yet
Fix from $1,950 2022-06-03
Ex1200t Firmware HIGH 7.5
CVE-2021-42891

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.

No fix yet
Fix from $1,950 2022-06-03
Ex1200t Firmware HIGH 7.5
CVE-2021-42889

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.

No fix yet
Fix from $1,950 2022-06-03
Meeting Owl Pro Firmware MEDIUM 6.5
CVE-2022-31461

Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message.

Fix: 5.4.2.3+
Fix from $1,600 2022-06-02
Control Room Management Suite MEDIUM 5.3
CVE-2022-26971

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This uplo…

Fix: 3.14.1+
Fix from $1,600 2022-06-02
Bleve MEDIUM 5.5
CVE-2022-31022

Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP …

Patch available
Fix from $1,600 2022-06-01
Curl HIGH 8.1
CVE-2022-22576

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections witho…

Fix: 7.83.0+
Fix from $1,950 2022-05-26
Oas Platform HIGH 7.5
CVE-2022-26067

An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.01…

No fix yet
Fix from $1,950 2022-05-25
Oas Platform CRITICAL 9.8
CVE-2022-26082EPSS 20%

A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A special…

No fix yet
Fix from $2,300 2022-05-25
Oas Platform HIGH 7.5
CVE-2022-26303

An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A…

No fix yet
Fix from $1,950 2022-05-25
Oas Platform CRITICAL 9.4
CVE-2022-26833EPSS 38%

An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-craft…

No fix yet
Fix from $2,300 2022-05-25
Oas Platform HIGH 7.5
CVE-2022-27169

An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112.…

No fix yet
Fix from $1,950 2022-05-25
Oas Platform HIGH 7.5
CVE-2022-26026

A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A s…

No fix yet
Fix from $1,950 2022-05-25
Oas Platform HIGH 7.5
CVE-2022-26043

An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.011…

No fix yet
Fix from $1,950 2022-05-25
Tl Wr840n Firmware MEDIUM 6.8
CVE-2022-29402

TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the…

No fix yet
Fix from $1,600 2022-05-25
Power System S922 Firmware MEDIUM 6.8
CVE-2022-22309

The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the s…

Fix: 860.b0 / 940.60+
Fix from $1,600 2022-05-24
Grafana CRITICAL 9.8
CVE-2022-28660

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…

Fix: 1.2.1+
Fix from $2,300 2022-05-20
7kg8500 0aa00 0aa0 Firmware MEDIUM 6.5
CVE-2022-29877

A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM…

Fix: 3.00+
Fix from $1,600 2022-05-20