Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Minio Console CRITICAL 9.8
CVE-2021-41266EPSS 48%

Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are s…

Fix: 0.12.3+
Fix from $2,300 2021-11-15
Manageengine Log360 CRITICAL 9.8
CVE-2021-20136EPSS 10%

ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthentica…

Fix: after 5.2
Fix from $2,300 2021-11-01
Dir 868lw Firmware MEDIUM 5.3
CVE-2021-33259

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query hi…

No fix yet
Fix from $1,600 2021-10-31
Freeswitch MEDIUM 5.3
CVE-2021-41157

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.6+
Fix from $1,600 2021-10-26
Freeswitch HIGH 7.5
CVE-2021-37624

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.7+
Fix from $1,950 2021-10-25
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-42539

The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved …

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Versiondog CRITICAL 9.8
CVE-2021-38457

The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing …

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Simatic Process Historian 2013 HIGH 8.1
CVE-2021-27395

A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 …

Mitigation only
Fix from $1,950 2021-10-12
Tad Web MEDIUM 6.5
CVE-2021-41568

Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin b…

Fix: after 1.76
Fix from $1,600 2021-10-08
Tad Book3 CRITICAL 9.1
CVE-2021-41974

Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content o…

Fix: 3.9+
Fix from $2,300 2021-10-08
Tadtools CRITICAL 9.1
CVE-2021-41975

TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the sy…

Fix: 3.2.2+
Fix from $2,300 2021-10-08
Tad Uploader MEDIUM 5.3
CVE-2021-41976

Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in t…

Fix: 3.5.4+
Fix from $1,600 2021-10-08
Realport HIGH 8.1
CVE-2021-35979

An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform auth…

Fix: after 4.8.488.0
Fix from $1,950 2021-10-08
Rexroth Indramotion Mlc L20 Firmware HIGH 7.5
CVE-2021-23858

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can …

Fix: after 12
Fix from $1,950 2021-10-04
Liderahenk CRITICAL 9.6
CVE-2021-3825

On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to…

Fix: after 2.1.15
Fix from $2,300 2021-10-01
Esphome Firmware HIGH 7.5
CVE-2021-41104

ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulne…

Fix: 2021.9.2+
Fix from $1,950 2021-09-28
Cloud Foundation HIGH 7.5
CVE-2021-22012

The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with networ…

Fix: 5.0+
Fix from $1,950 2021-09-23
Manageengine Admanager Plus MEDIUM 6.5
CVE-2021-37420

Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

Fix: 6.1+
Fix from $1,600 2021-09-21
Portserver Ts 16 Firmware CRITICAL 9.8
CVE-2021-38412

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require auth…

Mitigation only
Fix from $2,300 2021-09-17
Sinema Server MEDIUM 5.3
CVE-2019-10941

A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative …

Fix: 14.0+
Fix from $1,600 2021-09-14
G Cam Ebc 2110 Firmware CRITICAL 9.8
CVE-2021-33543EPSS 82%

Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user au…

Fix: after 1.12.0.27
Fix from $2,300 2021-09-13
Eibport Firmware CRITICAL 9.8
CVE-2021-28913

BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to validate the so called and har…

Fix: 3.9.1+
Fix from $2,300 2021-09-09
Airflow CRITICAL 9.8
CVE-2021-38540EPSS 81%

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint …

Fix: 2.1.3+
Fix from $2,300 2021-09-09
Nextcloud Server HIGH 8.1
CVE-2021-32800

Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextc…

Fix: 20.0.12 / 21.0.4+
Fix from $1,950 2021-09-07
Manageengine Servicedesk Plus CRITICAL 9.8
CVE-2021-37415 KEVEPSS 100%

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

Mitigation only
Fix from $2,300 2021-09-01
Vault MEDIUM 5.3
CVE-2021-27668

HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.

Fix: 1.6.3+
Fix from $1,600 2021-08-31
Spacecom2 HIGH 8.6
CVE-2021-33882

A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to reconfigure the de…

Fix: 012u000062+
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.5
CVE-2021-39144 KEVEPSS 98%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Nexpose MEDIUM 5.4
CVE-2021-31868

Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feat…

Fix: 6.6.96+
Fix from $1,600 2021-08-19
Airflow MEDIUM 5.3
CVE-2021-35936

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server…

Fix: 2.1.2+
Fix from $1,600 2021-08-16