Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.1 CVE-2022-41629 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could all… Infrasuite Device Master 00.00.02a+ Fix from $2,3002022-10-31 HIGH 8.8 CVE-2022-41644 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacke… Infrasuite Device Master 00.00.02a+ Fix from $1,9502022-10-31 HIGH 7.5 CVE-2022-41688 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that create and modify user groups. … Infrasuite Device Master 00.00.02a+ Fix from $1,9502022-10-31 HIGH 7.5 CVE-2022-41776 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which c… Infrasuite Device Master 00.00.02a+ Fix from $1,9502022-10-31 CRITICAL 9.8 CVE-2022-40202 The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper authentication. An attacker coul… Infrasuite Device Master 00.00.02a+ Fix from $2,3002022-10-31 HIGH 8.0 CVE-2022-2474 Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any use… Haas Controller Firmware Mitigation only Fix from $1,9502022-10-28 CRITICAL 9.8 CVE-2022-3674 A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an … Sanitization Management System Mitigation only Fix from $2,3002022-10-26 HIGH 7.5 CVE-2022-38870 Free5gc v3.2.1 is vulnerable to Information disclosure. Free5gc No fix yet Fix from $1,9502022-10-25 CRITICAL 9.1 CVE-2022-27623 Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 a… Diskstation Manager 7.1-42661+ Fix from $2,3002022-10-25 HIGH 8.1 CVE-2022-1070 Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials. Tug Home Base Server 24+ Fix from $1,9502022-10-21 CRITICAL 9.8 CVE-2022-3327 Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6. Rdiffweb 2.4.10+ Fix from $2,3002022-10-20 HIGH 7.5 CVE-2020-23648 Asus RT-N12E 2.0.0.39 is affected by an incorrect access control vulnerability. Through system.asp / start_apply.htm, an attacker can change the admi… Rt N12e Firmware No fix yet Fix from $1,9502022-10-19 HIGH 7.5 CVE-2022-39412 Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Admin Console). The supported version that is affected is … Access Manager Patch available Fix from $1,9502022-10-18 HIGH 8.1 CVE-2022-39425 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4… Vm Virtualbox 6.1.40+ Fix from $1,9502022-10-18 HIGH 8.1 CVE-2022-39426 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.4… Vm Virtualbox 6.1.40+ Fix from $1,9502022-10-18 CRITICAL 9.8 CVE-2022-21587 KEVEPSS 98% Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are a… E Business Suite after 12.2.11 Fix from $2,3002022-10-18 MEDIUM 6.5 CVE-2022-35136 Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests. Iot Platform No fix yet Fix from $1,6002022-10-13 MEDIUM 5.3 CVE-2022-20830 A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an una… Catalyst Sd Wan Manager 20.3.4.1 / 20.6.1+ Fix from $1,6002022-10-10 HIGH 7.5 CVE-2022-38817 Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data. Dapr Dashboard after 0.10.0 Fix from $1,9502022-10-03 CRITICAL 9.8 CVE-2022-22526 In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API. Cpy Car Park Server 2.8.3 / 8.5.0.3+ Fix from $2,3002022-09-28 MEDIUM 5.3 CVE-2022-36780 Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authentica… Crystal Quality No fix yet Fix from $1,6002022-09-13 HIGH 7.5 CVE-2022-35572 On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to code reuse), the /SysInfo.htm … E5350 Firmware after 1.0.00.037 Fix from $1,9502022-09-12 MEDIUM 5.4 CVE-2022-26394 The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middl… Spectrum Wireless Battery Module Firmware after 20d32 Fix from $1,6002022-09-09 CRITICAL 9.8 CVE-2022-1368 The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Func… 3d A1000 Dimensioning System Firmware after 1.0.3 Fix from $2,3002022-09-06 HIGH 8.1 CVE-2022-31176 Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). … Grafana Image Renderer 3.6.1+ Fix from $1,9502022-09-02 HIGH 7.5 CVE-2022-36604 An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily change user passwords via a c… Avalon Asic Miner Firmware after 2020.3.30 Fix from $1,9502022-09-01 HIGH 7.5 CVE-2022-36619 In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC. Dir 816 Firmware No fix yet Fix from $1,9502022-08-31 CRITICAL 9.1 CVE-2022-30317 Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experi… Experion Lx Firmware Mitigation only Fix from $2,3002022-08-31 HIGH 7.5 CVE-2022-37680 An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring system (Camera, Decoder and Encode… Hc Ip9100hd Firmware after 1.07 Fix from $1,9502022-08-29 HIGH 7.5 CVE-2022-36521 Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts. Cskefu No fix yet Fix from $1,9502022-08-26