Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.5 CVE-2023-38030 Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attac… Adm 100 Firmware Mitigation only Fix from $1,9502023-08-28 CRITICAL 9.1 CVE-2023-38028 Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to… Adm 100 Firmware Mitigation only Fix from $2,3002023-08-28 HIGH 7.5 CVE-2023-40585 ironic-image is a container image to run OpenStack Ironic as part of Metal³. Prior to version capm3-v1.4.3, if Ironic is not deployed with TLS and it… Ironic Image 1.4.3+ Fix from $1,9502023-08-25 HIGH 7.5 CVE-2023-38422 Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the management web server. This could a… Intuition 9 Firmware 4.21+ Fix from $1,9502023-08-23 MEDIUM 5.3 CVE-2023-36846 KEVEPSS 95% A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based atta… Junos 20.4+ Fix from $1,6002023-08-17 MEDIUM 5.3 CVE-2023-36847 KEVEPSS 86% A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attac… Junos 20.4+ Fix from $1,6002023-08-17 HIGH 7.5 CVE-2023-4334 Broadcom RAID Controller Web server (nginx) is serving private files without any authentication Raid Controller Web Interface Mitigation only Fix from $1,9502023-08-15 HIGH 7.5 CVE-2023-4335 Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux Raid Controller Web Interface Mitigation only Fix from $1,9502023-08-15 HIGH 7.5 CVE-2023-39380 Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. Emui No fix yet Fix from $1,9502023-08-13 CRITICAL 9.8 CVE-2023-38186 Windows Mobile Device Management Elevation of Privilege Vulnerability Windows 10 21h2 Patch available Fix from $2,3002023-08-08 HIGH 7.5 CVE-2023-37373 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications accept unauthenticated file write messages… Ruggedcom Crossbow 5.4+ Fix from $1,9502023-08-08 MEDIUM 5.8 CVE-2023-39436 SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relati… Supplier Relationship Management Mitigation only Fix from $1,6002023-08-08 MEDIUM 5.3 CVE-2023-36926 Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular c… Host Agent Mitigation only Fix from $1,6002023-08-08 CRITICAL 9.8 CVE-2023-37483 SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back… Powerdesigner Mitigation only Fix from $2,3002023-08-08 MEDIUM 5.3 CVE-2023-38523 The web interface on multiple Samsung Harman AMX N-Series devices allows directory listing for the /tmp/ directory, without authentication, exposing … Fgn1115 Wp Wh Firmware 1.15.61+ Fix from $1,6002023-07-20 HIGH 7.5 CVE-2023-22047EPSS 77% Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.… Peoplesoft Enterprise Patch available Fix from $1,9502023-07-18 HIGH 8.0 CVE-2023-34329 AMI MegaRAC SPx12 contains a vulnerability in BMC where a User may cause an authentication bypass by spoofing the HTTP header. A successful exploit o… Megarac Sp X Mitigation only Fix from $1,9502023-07-18 CRITICAL 9.8 CVE-2023-36669 Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary contro… Ngc Indoor Unit Firmware 11.4+ Fix from $2,3002023-07-18 CRITICAL 9.8 CVE-2023-37265EPSS 7% CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands … Casaos 0.4.4+ Fix from $2,3002023-07-17 HIGH 7.5 CVE-2023-38379 The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a z… Mso5000 Firmware No fix yet Fix from $1,9502023-07-16 HIGH 7.4 CVE-2023-35874 SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53,… Netweaver Application Server Abap Mitigation only Fix from $1,9502023-07-11 MEDIUM 6.5 CVE-2023-35872 The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain funct… Netweaver Process Integration Mitigation only Fix from $1,6002023-07-11 MEDIUM 6.5 CVE-2023-35873 The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functi… Netweaver Process Integration Mitigation only Fix from $1,6002023-07-11 HIGH 7.1 CVE-2023-30643 Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloade… Android Mitigation only Fix from $1,9502023-07-06 HIGH 8.8 CVE-2023-22906 Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password. Qubo Hcd01 Firmware No fix yet Fix from $1,9502023-07-04 HIGH 7.5 CVE-2023-36347EPSS 34% A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data. Codekop No fix yet Fix from $1,9502023-06-30 CRITICAL 9.8 CVE-2023-2834 The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verificat… Bookit after 2.3.7 Fix from $2,3002023-06-30 CRITICAL 9.8 CVE-2023-35830 STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite C… Tcg 4 Firmware Mitigation only Fix from $2,3002023-06-29 MEDIUM 6.5 CVE-2023-34761 An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the appl… Hello Cup No fix yet Fix from $1,6002023-06-28 CRITICAL 9.8 CVE-2023-35854EPSS 6% Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for… Manageengine Adselfservice Plus 6.1+ Fix from $2,3002023-06-20