Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Wallbox Gtb Firmware CRITICAL 9.1
CVE-2021-45878

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any use…

Fix: after 185
Fix from $2,300 2022-03-21
Piwigo HIGH 7.5
CVE-2022-26267

Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.

No fix yet
Fix from $1,950 2022-03-18
Ipados MEDIUM 6.1
CVE-2022-22652

The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock to interact with the GSMA auth…

Fix: 15.4+
Fix from $1,600 2022-03-18
Veeam Backup \& Replication CRITICAL 9.8
CVE-2022-26501 KEV

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

Fix: 10.0.1.4854 / 11.0.1.1261+
Fix from $2,300 2022-03-17
Wl Wn531g3 Firmware CRITICAL 9.8
CVE-2021-44259

A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access thi…

No fix yet
Fix from $2,300 2022-03-17
Wl Wn531g3 Firmware HIGH 7.5
CVE-2021-44260EPSS 7%

A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to acce…

No fix yet
Fix from $1,950 2022-03-17
Wac104 Firmware MEDIUM 5.3
CVE-2021-44261EPSS 20%

A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page wi…

Fix: after 1.1.0.34_1.0.1
Fix from $1,600 2022-03-17
Mbr1517 Firmware HIGH 7.5
CVE-2021-44262

A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page wit…

Fix: after 1.0.4.13
Fix from $1,950 2022-03-17
Axeda Agent CRITICAL 9.8
CVE-2022-25247

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port with…

Fix: 6.9.1 / 6.9.215+
Fix from $2,300 2022-03-16
Axeda Agent HIGH 7.5
CVE-2022-25250

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send a cert…

Fix: 6.9.1 / 6.9.215+
Fix from $1,950 2022-03-16
Axeda Agent CRITICAL 9.8
CVE-2022-25251

When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certai…

Fix: 6.9.1 / 6.9.215+
Fix from $2,300 2022-03-16
Atune HIGH 7.8
CVE-2021-33658

atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modif…

Fix: after 0.8
Fix from $1,950 2022-03-11
Freetakserver Ui HIGH 7.5
CVE-2022-25508

An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service…

No fix yet
Fix from $1,950 2022-03-11
Micollab CRITICAL 9.8
CVE-2022-26143 KEVEPSS 87%

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain s…

Fix: 9.4+
Fix from $2,300 2022-03-10
Plc4trucks Firmware CRITICAL 9.1
CVE-2022-25922

Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked by replaying J2497 messages.…

Mitigation only
Fix from $2,300 2022-03-10
Simple Diagnostics Agent HIGH 7.8
CVE-2022-24396

The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed v…

Fix: after 1.57
Fix from $1,950 2022-03-10
Android MEDIUM 6.6
CVE-2022-20060

In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privil…

Mitigation only
Fix from $1,600 2022-03-10
Mcms CRITICAL 9.8
CVE-2021-46384

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker…

Fix: after 5.2.5
Fix from $2,300 2022-03-04
Scadaflex Ii Firmware CRITICAL 9.1
CVE-2022-25359EPSS 37%

On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.

No fix yet
Fix from $2,300 2022-02-26
Openenterprise Scada Server CRITICAL 9.8
CVE-2020-10640

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execut…

Fix: after 3.3.4
Fix from $2,300 2022-02-24
Antd Admin HIGH 7.5
CVE-2021-46371

antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage …

No fix yet
Fix from $1,950 2022-02-14
Dixell Xweb 500 Firmware CRITICAL 9.8
CVE-2021-45420EPSS 18%

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cg…

Mitigation only
Fix from $2,300 2022-02-14
Cmp MEDIUM 5.3
CVE-2022-0188

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

Fix: 4.0.19+
Fix from $1,600 2022-02-14
Interactive Graphical Scada System Data Collector CRITICAL 9.1
CVE-2021-22805

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user …

Fix: after 15.0.0.21243
Fix from $2,300 2022-02-11
Interactive Graphical Scada System Data Collector CRITICAL 9.1
CVE-2021-22823EPSS 21%

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user …

Fix: after 15.0.0.21320
Fix from $2,300 2022-02-11
Stormshield Network Security MEDIUM 6.1
CVE-2021-31814

In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the…

Fix: after 2.9.0
Fix from $1,600 2022-02-10
Mahara MEDIUM 5.3
CVE-2022-24111

In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios…

Fix: 21.04.3+
Fix from $1,600 2022-02-10
Spacelynk Firmware MEDIUM 5.3
CVE-2022-22809

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unautho…

Fix: after 2.6.2
Fix from $1,600 2022-02-09
Cloud Gaming Virtual Gpu MEDIUM 5.5
CVE-2022-21816

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on…

Fix: 8.10 / 11.7+
Fix from $1,600 2022-02-07
Seaconnect 370w Firmware HIGH 7.4
CVE-2021-21964

A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-craft…

No fix yet
Fix from $1,950 2022-02-04