Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.6 CVE-2023-22441 Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the set… Skybridge Basic Mb A130 Firmware after 1.4.1 Fix from $1,9502023-05-10 CRITICAL 9.8 CVE-2023-31143 mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72… Mage Ai 0.8.72+ Fix from $2,3002023-05-09 CRITICAL 9.1 CVE-2023-30744 In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and… Netweaver Application Server For Java Mitigation only Fix from $2,3002023-05-09 CRITICAL 9.8 CVE-2023-20126EPSS 37% A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execut… Spa112 Firmware Mitigation only Fix from $2,3002023-05-04 HIGH 7.5 CVE-2023-31444 In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the micro… Studio 7.3.1-r2022-10 / 8.0.1-r2022-09+ Fix from $1,9502023-04-28 CRITICAL 9.8 CVE-2023-28697 Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitr… Miineport E1 Firmware Mitigation only Fix from $2,3002023-04-27 MEDIUM 6.1 CVE-2022-40725 PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted… Desktop 1.7.4+ Fix from $1,6002023-04-25 CRITICAL 9.8 CVE-2023-2231 A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component… Max G866ac Firmware Mitigation only Fix from $2,3002023-04-21 CRITICAL 9.8 CVE-2023-23451 The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FL… Ue410 En3 Firmware after 2.12.0 Fix from $2,3002023-04-19 CRITICAL 9.8 CVE-2023-29411 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to poten… Apc Easy Ups Online Monitoring Software after 2.5-gs-01-22320 Fix from $2,3002023-04-18 HIGH 7.5 CVE-2023-29413 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated u… Apc Easy Ups Online Monitoring Software after 2.5-gs-01-22320 Fix from $1,9502023-04-18 HIGH 7.5 CVE-2023-21979 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3… Weblogic Server Mitigation only Fix from $1,9502023-04-18 HIGH 7.5 CVE-2023-21931EPSS 82% Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3… Weblogic Server Patch available Fix from $1,9502023-04-18 MEDIUM 5.3 CVE-2023-27571 An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionali… Dg3450 Firmware No fix yet Fix from $1,6002023-04-15 MEDIUM 5.5 CVE-2023-24934 Microsoft Defender Security Feature Bypass Vulnerability Malware Protection Platform 4.18.2303.8+ Fix from $1,6002023-04-14 HIGH 7.5 CVE-2023-27747 BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive i… Dr750 2ch Lte Firmware No fix yet Fix from $1,9502023-04-13 CRITICAL 9.8 CVE-2022-41331 A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, u… Fortiproxy 2.0.0+ Fix from $2,3002023-04-11 MEDIUM 5.3 CVE-2023-24527 SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity ena… Netweaver As Java For Deploy Service Mitigation only Fix from $1,6002023-04-11 HIGH 8.1 CVE-2023-27267EPSS 14% Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with… Diagnostics Agent Mitigation only Fix from $1,9502023-04-11 CRITICAL 9.8 CVE-2023-27497 Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker … Diagnostics Agent Mitigation only Fix from $2,3002023-04-11 MEDIUM 6.5 CVE-2023-28761 In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access … Netweaver Enterprise Portal Mitigation only Fix from $1,6002023-04-11 HIGH 7.5 CVE-2020-14140 When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is ca… Xiaomi Router Firmware 2023.2+ Fix from $1,9502023-03-29 CRITICAL 9.8 CVE-2022-36983 This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to … Avalanche 6.3.4+ Fix from $2,3002023-03-29 HIGH 8.8 CVE-2022-27645 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is… Lax20 Firmware 1.0.4.84 / 1.0.4.126+ Fix from $1,9502023-03-29 CRITICAL 9.8 CVE-2023-28326 Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privi… Openmeetings 7.0.0+ Fix from $2,3002023-03-28 MEDIUM 6.5 CVE-2022-48291 The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect conf… Emui No fix yet Fix from $1,6002023-03-27 CRITICAL 9.8 CVE-2023-1140 Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated re… Infrasuite Device Master 1.0.5+ Fix from $2,3002023-03-27 CRITICAL 9.8 CVE-2023-24838 HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini… Powerstation Firmware Mitigation only Fix from $2,3002023-03-27 MEDIUM 5.3 CVE-2023-28470 In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. Couchbase Server 7.1.4+ Fix from $1,6002023-03-23 CRITICAL 9.8 CVE-2023-27060 LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function. Lightcms Patch available Fix from $2,3002023-03-22