Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
7kg8500 0aa00 0aa0 Firmware MEDIUM 5.3
CVE-2022-29881

A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special …

Fix: 3.00+
Fix from $1,600 2022-05-20
7kg8500 0aa00 0aa0 Firmware MEDIUM 5.3
CVE-2022-29883

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the…

Fix: 3.00+
Fix from $1,600 2022-05-20
Windows 10 1507 MEDIUM 5.9
CVE-2022-26925 KEVEPSS 11%

Windows LSA Spoofing Vulnerability

Fix: 10.0.10240.19297 / 10.0.14393.5125+
Fix from $1,600 2022-05-10
Popup MEDIUM 5.3
CVE-2022-0424

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated …

Fix: 1.10.9+
Fix from $1,600 2022-05-09
Nginx Service Mesh MEDIUM 6.5
CVE-2022-27495

On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2022-1388 KEVEPSS 100%

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…

Fix: 13.1.5 / 14.1.4.6+
Fix from $2,300 2022-05-05
Trutops Boost CRITICAL 9.8
CVE-2022-1300

Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unau…

Fix: after 22.05
Fix from $2,300 2022-05-02
Oracle Optimization HIGH 7.8
CVE-2022-29934

USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is…

No fix yet
Fix from $1,950 2022-04-29
Lexmark Firmware HIGH 7.5
CVE-2022-24935

Lexmark products through 2022-02-10 have Incorrect Access Control.

Fix: after 2022-02-10
Fix from $1,950 2022-04-28
Assetview CRITICAL 9.8
CVE-2022-28719

Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the sys…

Fix: 13.2.0+
Fix from $2,300 2022-04-28
Zammad CRITICAL 9.1
CVE-2022-27332

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow…

Fix: 5.1.0+
Fix from $2,300 2022-04-27
Tatsu HIGH 8.1
CVE-2021-25094EPSS 83%

The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompre…

Fix: 3.3.12+
Fix from $1,950 2022-04-25
Security Optimizer CRITICAL 9.8
CVE-2022-0992

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use…

Fix: 1.2.6+
Fix from $2,300 2022-04-19
Siteground Security CRITICAL 9.8
CVE-2022-0993EPSS 7%

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use…

Fix: after 1.2.5
Fix from $2,300 2022-04-19
Visual Form Builder MEDIUM 5.3
CVE-2022-0140

The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the…

Fix: 3.0.6+
Fix from $1,600 2022-04-12
Combined Charging System Firmware MEDIUM 6.5
CVE-2022-0878

Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of…

Fix: after 2.0
Fix from $1,600 2022-04-12
Garden CRITICAL 9.8
CVE-2022-24829

Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authenticati…

Fix: 0.12.39+
Fix from $2,300 2022-04-11
Xwiki MEDIUM 5.3
CVE-2022-24820

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages…

Fix: 12.10.11 / 13.4.4+
Fix from $1,600 2022-04-08
Kaon Cg3000 Firmware HIGH 8.0
CVE-2021-43483

An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update…

No fix yet
Fix from $1,950 2022-04-08
Icheck Connect Bp Monitor Bp Testing 118 Firmware HIGH 8.8
CVE-2020-27376

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.

Mitigation only
Fix from $1,950 2022-04-07
Sap Information System HIGH 7.3
CVE-2022-1248

A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/…

No fix yet
Fix from $1,950 2022-04-06
Manageengine Servicedesk Plus MEDIUM 5.3
CVE-2022-25245

Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.

Fix: after 12.0
Fix from $1,600 2022-04-05
System Platform CRITICAL 9.8
CVE-2021-33008

AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.

Fix: 2020+
Fix from $2,300 2022-04-04
E Alert Firmware MEDIUM 6.5
CVE-2022-0922

The software does not perform any authentication for critical system functionality.

Fix: 2.7+
Fix from $1,600 2022-04-01
Ignition MEDIUM 5.3
CVE-2020-14479

Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to q…

Fix: 7.9.14+
Fix from $1,600 2022-04-01
Ex300 V2 Firmware HIGH 8.8
CVE-2022-25008

totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.

No fix yet
Fix from $1,950 2022-03-30
A3100r Firmware MEDIUM 6.5
CVE-2021-46006EPSS 5%

In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure m…

No fix yet
Fix from $1,600 2022-03-30
A3100r Firmware CRITICAL 9.8
CVE-2021-46009EPSS 13%

In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set…

Mitigation only
Fix from $2,300 2022-03-30
Satellite HIGH 8.0
CVE-2021-3589

An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access host…

Fix: 7.1.0+
Fix from $1,950 2022-03-23
Bigant Server HIGH 7.5
CVE-2022-23345

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

No fix yet
Fix from $1,950 2022-03-21