Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2022-41629
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could all…
Infrasuite Device Master
00.00.02a+
HIGH 8.8
CVE-2022-41644
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacke…
Infrasuite Device Master
00.00.02a+
HIGH 7.5
CVE-2022-41688
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. …
Infrasuite Device Master
00.00.02a+
HIGH 7.5
CVE-2022-41776
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which c…
Infrasuite Device Master
00.00.02a+
CRITICAL 9.8
CVE-2022-40202
The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker coul…
Infrasuite Device Master
00.00.02a+
HIGH 8.0
CVE-2022-2474
Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any use…
Haas Controller Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-3674
A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an …
Sanitization Management System
Mitigation only
HIGH 7.5
CVE-2022-38870
Free5gc v3.2.1 is vulnerable to Information disclosure.
Free5gc
No fix yet
CRITICAL 9.1
CVE-2022-27623
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 a…
Diskstation Manager
7.1-42661+
HIGH 8.1
CVE-2022-1070
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
Tug Home Base Server
24+
CRITICAL 9.8
CVE-2022-3327
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
Rdiffweb
2.4.10+
HIGH 7.5
CVE-2020-23648
Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the admi…
Rt N12e Firmware
No fix yet
HIGH 7.5
CVE-2022-39412
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affected is …
Access Manager
Patch available
HIGH 8.1
CVE-2022-39425
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4…
Vm Virtualbox
6.1.40+
HIGH 8.1
CVE-2022-39426
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4…
Vm Virtualbox
6.1.40+
CRITICAL 9.8
CVE-2022-21587 KEVEPSS 98%
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are a…
E Business Suite
after 12.2.11
MEDIUM 6.5
CVE-2022-35136
Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.
Iot Platform
No fix yet
MEDIUM 5.3
CVE-2022-20830
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an una…
Catalyst Sd Wan Manager
20.3.4.1 / 20.6.1+
HIGH 7.5
CVE-2022-38817
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
Dapr Dashboard
after 0.10.0
CRITICAL 9.8
CVE-2022-22526
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.
Cpy Car Park Server
2.8.3 / 8.5.0.3+
MEDIUM 5.3
CVE-2022-36780
Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authentica…
Crystal Quality
No fix yet
HIGH 7.5
CVE-2022-35572
On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm …
E5350 Firmware
after 1.0.00.037
MEDIUM 5.4
CVE-2022-26394
The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middl…
Spectrum Wireless Battery Module Firmware
after 20d32
CRITICAL 9.8
CVE-2022-1368
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Func…
3d A1000 Dimensioning System Firmware
after 1.0.3
HIGH 8.1
CVE-2022-31176
Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). …
Grafana Image Renderer
3.6.1+
HIGH 7.5
CVE-2022-36604
An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a c…
Avalon Asic Miner Firmware
after 2020.3.30
HIGH 7.5
CVE-2022-36619
In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
Dir 816 Firmware
No fix yet
CRITICAL 9.1
CVE-2022-30317
Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experi…
Experion Lx Firmware
Mitigation only
HIGH 7.5
CVE-2022-37680
An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring system (Camera, Decoder and Encode…
Hc Ip9100hd Firmware
after 1.07
HIGH 7.5
CVE-2022-36521
Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.
Cskefu
No fix yet