Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.6
CVE-2023-22441
Missing authentication for critical function exists in Seiko Solutions SkyBridge series, which may allow a remote attacker to obtain or alter the set…
Skybridge Basic Mb A130 Firmware
after 1.4.1
CRITICAL 9.8
CVE-2023-31143
mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72…
Mage Ai
0.8.72+
CRITICAL 9.1
CVE-2023-30744
In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and…
Netweaver Application Server For Java
Mitigation only
CRITICAL 9.8
CVE-2023-20126EPSS 37%
A vulnerability in the web-based management interface of Cisco SPA112 2-Port Phone Adapters could allow an unauthenticated, remote attacker to execut…
Spa112 Firmware
Mitigation only
HIGH 7.5
CVE-2023-31444
In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the micro…
Studio
7.3.1-r2022-10 / 8.0.1-r2022-09+
CRITICAL 9.8
CVE-2023-28697
Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitr…
Miineport E1 Firmware
Mitigation only
MEDIUM 6.1
CVE-2022-40725
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted…
Desktop
1.7.4+
CRITICAL 9.8
CVE-2023-2231
A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component…
Max G866ac Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-23451
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FL…
Ue410 En3 Firmware
after 2.12.0
CRITICAL 9.8
CVE-2023-29411
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to poten…
Apc Easy Ups Online Monitoring Software
after 2.5-gs-01-22320
HIGH 7.5
CVE-2023-29413
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause
Denial-of-Service when accessed by an unauthenticated u…
Apc Easy Ups Online Monitoring Software
after 2.5-gs-01-22320
HIGH 7.5
CVE-2023-21979
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…
Weblogic Server
Mitigation only
HIGH 7.5
CVE-2023-21931EPSS 82%
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…
Weblogic Server
Patch available
MEDIUM 5.3
CVE-2023-27571
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionali…
Dg3450 Firmware
No fix yet
MEDIUM 5.5
CVE-2023-24934
Microsoft Defender Security Feature Bypass Vulnerability
Malware Protection Platform
4.18.2303.8+
HIGH 7.5
CVE-2023-27747
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive i…
Dr750 2ch Lte Firmware
No fix yet
CRITICAL 9.8
CVE-2022-41331
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, u…
Fortiproxy
2.0.0+
MEDIUM 5.3
CVE-2023-24527
SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity ena…
Netweaver As Java For Deploy Service
Mitigation only
HIGH 8.1
CVE-2023-27267EPSS 14%
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with…
Diagnostics Agent
Mitigation only
CRITICAL 9.8
CVE-2023-27497
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker …
Diagnostics Agent
Mitigation only
MEDIUM 6.5
CVE-2023-28761
In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access …
Netweaver Enterprise Portal
Mitigation only
HIGH 7.5
CVE-2020-14140
When Xiaomi router firmware is updated in 2020, there is an unauthenticated API that can reveal WIFI password vulnerability. This vulnerability is ca…
Xiaomi Router Firmware
2023.2+
CRITICAL 9.8
CVE-2022-36983
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to …
Avalanche
6.3.4+
HIGH 8.8
CVE-2022-27645
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 routers. Authentication is…
Lax20 Firmware
1.0.4.84 / 1.0.4.126+
CRITICAL 9.8
CVE-2023-28326
Vendor: The Apache Software Foundation
Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0
Description: Attacker can elevate their privi…
Openmeetings
7.0.0+
MEDIUM 6.5
CVE-2022-48291
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect conf…
Emui
No fix yet
CRITICAL 9.8
CVE-2023-1140
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated re…
Infrasuite Device Master
1.0.5+
CRITICAL 9.8
CVE-2023-24838
HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the admini…
Powerstation Firmware
Mitigation only
MEDIUM 5.3
CVE-2023-28470
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
Couchbase Server
7.1.4+
CRITICAL 9.8
CVE-2023-27060
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
Lightcms
Patch available