Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Motioneye HIGH 7.2
CVE-2021-44255

Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup fil…

Fix: 0.42.1 / 20200606+
Fix from $1,950 2022-01-31
Deltav Workstation MEDIUM 5.5
CVE-2021-26264

A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service cond…

No fix yet
Fix from $1,600 2022-01-28
Xr1000 MEDIUM 6.5
CVE-2021-34870

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 ro…

Patch available
Fix from $1,600 2022-01-25
Shenyu CRITICAL 9.1
CVE-2022-23944EPSS 79%

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $2,300 2022-01-25
Shenyu HIGH 7.5
CVE-2022-23945

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Patch available
Fix from $1,950 2022-01-25
Agilia Sp Mc Wifi Firmware MEDIUM 5.3
CVE-2021-33843

Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this function…

Mitigation only
Fix from $1,600 2022-01-21
Usbview HIGH 7.8
CVE-2022-23220

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g.…

Fix: 2.2+
Fix from $1,950 2022-01-21
Amc2 Firmware HIGH 7.8
CVE-2021-23843

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a pa…

Fix: 4.9.1+
Fix from $1,950 2022-01-19
Access Manager CRITICAL 9.8
CVE-2021-35587 KEVEPSS 96%

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 1…

Mitigation only
Fix from $2,300 2022-01-19
Eos CRITICAL 9.1
CVE-2021-28506

An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially…

Fix: after 4.26.2f
Fix from $2,300 2022-01-14
Nvrmini2 Firmware CRITICAL 9.8
CVE-2022-23227 KEVEPSS 49%

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because …

Fix: after 3.11.0
Fix from $2,300 2022-01-14
Itil MEDIUM 5.3
CVE-2021-43974

An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the serv…

No fix yet
Fix from $1,600 2022-01-11
Spinnaker CRITICAL 9.8
CVE-2021-43832

Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. Thi…

Fix: 1.25.8 / 1.26.7+
Fix from $2,300 2022-01-04
Dxu MEDIUM 6.5
CVE-2021-43333

The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration …

Fix: after 2.1.3
Fix from $1,600 2022-01-01
Tew 827dru Firmware MEDIUM 6.8
CVE-2021-20161

Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to…

Mitigation only
Fix from $1,600 2021-12-30
Tew 827dru Firmware MEDIUM 5.3
CVE-2021-20150EPSS 40%

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and…

Mitigation only
Fix from $1,600 2021-12-30
Tew 827dru Firmware MEDIUM 6.5
CVE-2021-20152

Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modif…

Mitigation only
Fix from $1,600 2021-12-30
Tew 827dru Firmware CRITICAL 9.8
CVE-2021-20158EPSS 11%

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to …

Mitigation only
Fix from $2,300 2021-12-30
Apisix Dashboard CRITICAL 9.8
CVE-2021-45232EPSS 86%

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all…

Fix: 2.10.1+
Fix from $2,300 2021-12-27
Longhorn HIGH 8.1
CVE-2021-36780

A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica in…

Fix: 1.1.3 / 1.2.3+
Fix from $1,950 2021-12-17
Longhorn CRITICAL 9.6
CVE-2021-36779

A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the…

Fix: 1.1.3 / 1.2.3+
Fix from $2,300 2021-12-17
Image Hover Effects CRITICAL 9.8
CVE-2021-36888EPSS 7%

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6…

Fix: 9.6.1+
Fix from $2,300 2021-12-15
Omnicore C30 Firmware CRITICAL 9.8
CVE-2021-22279

A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot contro…

Fix: 7.3.2+
Fix from $2,300 2021-12-13
Reprise License Manager CRITICAL 9.8
CVE-2021-44152EPSS 59%

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthentica…

Fix: 15.1+
Fix from $2,300 2021-12-13
Solar Log 500 Firmware HIGH 7.5
CVE-2021-34543

The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administr…

Fix: after 2.8.1
Fix from $1,950 2021-12-07
Holmes HIGH 7.5
CVE-2021-38147EPSS 53%

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive inform…

No fix yet
Fix from $1,950 2021-11-29
Holmes HIGH 7.5
CVE-2021-38283

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a pre…

No fix yet
Fix from $1,950 2021-11-29
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-44077 KEVEPSS 93%

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentic…

Fix: 10.5 / 11.0+
Fix from $2,300 2021-11-29
Dwr 932c E1 Firmware CRITICAL 9.8
CVE-2021-42783

Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to…

Fix: after 1.0.0.4
Fix from $2,300 2021-11-23
Ozone CRITICAL 9.1
CVE-2021-39233

In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any …

Fix: 1.2.0+
Fix from $2,300 2021-11-19