Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 6.5 CVE-2021-37234 Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensit… Modern Honey Network 2021-10-30+ Fix from $1,6002023-02-03 HIGH 7.5 CVE-2023-25013 An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit… Femanager 5.5.3 / 6.3.4+ Fix from $1,9502023-02-02 HIGH 7.5 CVE-2023-25014 An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the Invit… Femanager 5.5.3 / 6.3.4+ Fix from $1,9502023-02-02 CRITICAL 9.8 CVE-2022-42970 A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable u… Apc Easy Ups Online Monitoring Software 2.5-ga / 2.5-gs+ Fix from $2,3002023-02-01 CRITICAL 9.1 CVE-2022-32528 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGS… Interactive Graphical Scada System after 15.0.0.22170 Fix from $2,3002023-01-30 HIGH 7.5 CVE-2021-43447 ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to… Server after 7.0.0.49 Fix from $1,9502023-01-23 MEDIUM 6.4 CVE-2022-41505 An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by connecting to the UART pins, i… Tapo C200 V1 Firmware No fix yet Fix from $1,6002023-01-23 HIGH 8.8 CVE-2023-0052 SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands w… Nova 220 Eyk220f001 Firmware after 3.3-006 Fix from $1,9502023-01-20 MEDIUM 6.5 CVE-2020-22661 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10… R310 Firmware 3.6.2.0.795+ Fix from $1,6002023-01-20 CRITICAL 9.8 CVE-2020-23256 An issue was discovered in Electerm 1.3.22, allows attackers to execute arbitrary code via unverified request to electerms service. Electerm Patch available Fix from $2,3002023-01-20 MEDIUM 5.9 CVE-2022-3738 The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive informa… Pfc100 Firmware after 22 Fix from $1,6002023-01-19 HIGH 7.5 CVE-2023-21856 Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that… Isetup after 12.2.12 Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21837 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3… Weblogic Server Patch available Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21839 KEVEPSS 100% Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3… Weblogic Server Patch available Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-21842 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are… Weblogic Server Patch available Fix from $1,9502023-01-18 CRITICAL 9.8 CVE-2022-46732 Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status. Proficy Historian 2023+ Fix from $2,3002023-01-18 CRITICAL 9.8 CVE-2022-43976 An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possibl… Ms 3000 Firmware 3.7.6.25p0_3.2.2.17p0_4.7p0+ Fix from $2,3002023-01-17 HIGH 8.2 CVE-2022-42276 NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which… Dgx A100 Firmware 1.18+ Fix from $1,9502023-01-13 HIGH 8.2 CVE-2022-42277 NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, wh… Dgx Station A100 Firmware 10.16+ Fix from $1,9502023-01-13 HIGH 7.1 CVE-2022-42275 NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of inte… Bmc 00.19.07+ Fix from $1,9502023-01-13 HIGH 7.5 CVE-2022-46463EPSS 6% An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the… Harbor after 2.5.3 Fix from $1,9502023-01-13 MEDIUM 5.3 CVE-2023-21743 Microsoft SharePoint Server Security Feature Bypass Vulnerability Sharepoint Server No fix yet Fix from $1,6002023-01-10 HIGH 7.5 CVE-2022-45423 Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain encrypted MQTT credentials b… Dss Express Patch available Fix from $1,9502022-12-27 MEDIUM 5.3 CVE-2022-45424 Some Dahua software products have a vulnerability of unauthenticated request of AES crypto key. An attacker can obtain the AES crypto key by sending … Dss Express Patch available Fix from $1,6002022-12-27 MEDIUM 5.3 CVE-2022-45432 Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sendi… Dhi Dss7016d S2 Firmware Patch available Fix from $1,6002022-12-27 CRITICAL 9.1 CVE-2022-44013 An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authentication because the password … Lieferantenmanager 5.6+ Fix from $2,3002022-12-25 MEDIUM 5.3 CVE-2022-3188 Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authent… Iboot Pdu4 N20 Firmware 1.42.06162022+ Fix from $1,6002022-12-21 CRITICAL 9.8 CVE-2022-47377 Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain acc… Sim2000 Firmware 1.13.4+ Fix from $2,3002022-12-16 MEDIUM 5.3 CVE-2022-31701 VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be… Access Mitigation only Fix from $1,6002022-12-14 HIGH 8.6 CVE-2022-41272 An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver P… Netweaver Process Integration Mitigation only Fix from $1,9502022-12-13