Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2023-26571 Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and earlier allows modification of student data by unau… Idweb after 3.1.052 Fix from $1,9502023-10-25 CRITICAL 9.1 CVE-2023-26573 Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login cr… Idweb after 3.1.052 Fix from $2,3002023-10-25 HIGH 7.5 CVE-2023-26574 Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by u… Idweb after 3.1.052 Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-26575 Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and… Idweb after 3.1.052 Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-26576 Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student dat… Idweb after 3.1.052 Fix from $1,9502023-10-25 MEDIUM 5.3 CVE-2023-26579 Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows deletion of staff information by unauthenticated atta… Idweb Mitigation only Fix from $1,6002023-10-25 HIGH 7.5 CVE-2023-26580 Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthe… Idweb after 3.1.052 Fix from $1,9502023-10-25 HIGH 7.5 CVE-2023-43045 IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized actions due to improper authenticat… Sterling Partner Engagement Manager Patch available Fix from $1,9502023-10-23 HIGH 8.1 CVE-2023-22101 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Patch available Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-22087 Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version tha… Hospitality Opera 5 Property Services Patch available Fix from $1,9502023-10-17 CRITICAL 9.8 CVE-2023-22069 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Patch available Fix from $2,3002023-10-17 CRITICAL 9.8 CVE-2023-22072 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1… Weblogic Server Patch available Fix from $2,3002023-10-17 CRITICAL 9.8 CVE-2023-44116 Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some … Harmonyos No fix yet Fix from $2,3002023-10-11 CRITICAL 9.1 CVE-2023-43271 Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp a… A500s Firmware No fix yet Fix from $2,3002023-10-09 HIGH 7.5 CVE-2023-4884 An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication. Open5gs after 2.4.10 Fix from $1,9502023-10-03 MEDIUM 6.5 CVE-2023-4506 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. Thi… Active Directory Integration \/ Ldap Integration after 4.1.10 Fix from $1,6002023-09-27 CRITICAL 9.1 CVE-2023-44152 Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linu… Cyber Protect 15+ Fix from $2,3002023-09-27 HIGH 8.1 CVE-2023-41333 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to create or modify CiliumNet… Cilium 1.12.14 / 1.13.7+ Fix from $1,9502023-09-27 MEDIUM 5.3 CVE-2023-36851 KEV A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta… Junos Mitigation only Fix from $1,6002023-09-27 CRITICAL 9.8 CVE-2023-43644 Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-b… Sing Box 1.4.5+ Fix from $2,3002023-09-25 CRITICAL 9.8 CVE-2023-42793 KEVEPSS 100% In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible Teamcity 2023.05.4+ Fix from $2,3002023-09-19 CRITICAL 9.8 CVE-2023-4702 Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digit… Digital Yepas 1.0.1+ Fix from $2,3002023-09-14 HIGH 7.8 CVE-2023-4516 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change u… Interactive Graphical Scada System after 16.0.0.23211 Fix from $1,9502023-09-14 MEDIUM 5.3 CVE-2023-41367 Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain acce… Netweaver Mitigation only Fix from $1,6002023-09-12 HIGH 8.8 CVE-2023-4815 Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3. Answer 1.1.3+ Fix from $1,9502023-09-07 HIGH 7.8 CVE-2023-31132 Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability.… Cacti 1.2.25+ Fix from $1,9502023-09-05 HIGH 7.5 CVE-2023-39981 A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadeq… Mxsecurity after 1.0.1 Fix from $1,9502023-09-02 HIGH 8.8 CVE-2023-34392 A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an… Sel 5037 Sel Grid Configurator 4.5.0.20+ Fix from $1,9502023-08-31 HIGH 8.8 CVE-2023-40598 In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The at… Splunk 8.2.12 / 9.0.6+ Fix from $1,9502023-08-30 MEDIUM 6.1 CVE-2023-40170 jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain f… Jupyter Server 2.7.2+ Fix from $1,6002023-08-28