Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 6.8 CVE-2024-20391 A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an … Secure Client 5.1.3.62+ Fix from $1,6002024-05-15 HIGH 7.4 CVE-2023-5935 When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks aut… Mitigation only Fix from $1,9502024-05-15 HIGH 7.5 CVE-2024-27942 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any unauthenticated client to disconnect … Ruggedcom Crossbow 5.5+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-32735EPSS 7% An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote… Powerpanel 2.8.3+ Fix from $2,3002024-05-14 HIGH 7.6 CVE-2022-32503 An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the devi… Mitigation only Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2024-1076 The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .h… Ssl Zen 4.6.0+ Fix from $1,6002024-05-08 HIGH 7.8 CVE-2024-2860 The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing… Brocade Sannav 2.3.0a+ Fix from $1,9502024-05-08 MEDIUM 5.4 CVE-2023-37325 D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized cha… Dap 2622 Firmware Mitigation only Fix from $1,6002024-05-07 MEDIUM 6.5 CVE-2021-34983 NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability. This vulnerability allows network-a… Xr1000 Firmware 1.0.0.62 / 1.0.0.64+ Fix from $1,6002024-05-07 HIGH 7.6 CVE-2024-3661 DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redi… Forticlient 1.5.1.25 / 3.7.0.134+ Fix from $1,9502024-05-06 HIGH 7.5 CVE-2023-51587EPSS 36% Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers t… Viewpower Mitigation only Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-50199 D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attack… G416 Firmware 1.09b01+ Fix from $1,9502024-05-03 HIGH 7.5 CVE-2023-44413 D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a deni… D View 8 Mitigation only Fix from $1,9502024-05-03 CRITICAL 9.8 CVE-2023-42121 Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on… Webpanel Mitigation only Fix from $2,3002024-05-03 MEDIUM 6.5 CVE-2023-41186 D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to access vario… Dap 1325 Firmware 1.09b03+ Fix from $1,6002024-05-03 HIGH 8.8 CVE-2023-41187 D-Link DAP-1325 HNAP Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbi… Dap 1325 Firmware 1.09b03+ Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-41183EPSS 15% NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affec… Rbr760 Firmware 6.3.8.5+ Fix from $1,9502024-05-03 MEDIUM 5.3 CVE-2023-39466 Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attac… Scada Data Gateway Mitigation only Fix from $1,6002024-05-03 CRITICAL 9.8 CVE-2023-39457 Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on a… Scada Data Gateway Mitigation only Fix from $2,3002024-05-03 HIGH 8.8 CVE-2023-38123 Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability. This vulnerabilit… Ignition 8.1.26+ Fix from $1,9502024-05-03 MEDIUM 6.5 CVE-2023-27357 NETGEAR RAX30 GetInfo Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose s… Rax30 Firmware 1.0.10.94+ Fix from $1,6002024-05-03 HIGH 8.8 CVE-2023-47166 A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request… Ur32l Firmware Mitigation only Fix from $1,9502024-05-01 CRITICAL 9.9 CVE-2024-32764 A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allo… Myqnapcloud Link 2.4.51+ Fix from $2,3002024-04-26 CRITICAL 9.8 CVE-2023-51478 Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a thro… Build App Online 1.0.20+ Fix from $2,3002024-04-25 HIGH 7.5 CVE-2024-1491 The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system … Mitigation only Fix from $1,9502024-04-18 MEDIUM 5.3 CVE-2024-21846 An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET request to the command.cgi gatew… Mitigation only Fix from $1,6002024-04-18 CRITICAL 9.8 CVE-2024-21014 Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported… Hospitality Simphony after 19.5.4 Fix from $2,3002024-04-16 HIGH 7.5 CVE-2024-21006EPSS 8% Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-21007 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Mitigation only Fix from $1,9502024-04-16 HIGH 7.5 CVE-2023-4857 An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that c… Mitigation only Fix from $1,9502024-04-15