Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2022-35733 Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1… Udr Ja1004 Firmware after 2.0.20.13 Fix from $2,3002022-08-23 CRITICAL 9.8 CVE-2022-34858 Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress. Oauth 2.0 Client For Sso 1.11.4+ Fix from $2,3002022-08-22 MEDIUM 5.3 CVE-2022-2552EPSS 11% The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve… Duplicator 1.4.7.1+ Fix from $1,6002022-08-22 HIGH 7.5 CVE-2022-37062 All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory… Flir Ax8 Firmware after 1.46.16 Fix from $1,9502022-08-18 CRITICAL 9.1 CVE-2022-35122 An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information i… Gw1100 Firmware after 2.1.5 Fix from $2,3002022-08-17 CRITICAL 9.8 CVE-2022-2765 A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown f… Company Website Cms No fix yet Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-2242 The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write … Systemsoftware V\/kss 8.6.5+ Fix from $2,3002022-08-10 CRITICAL 9.8 CVE-2022-35865 This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re… Track It\! Patch available Fix from $2,3002022-08-03 HIGH 7.5 CVE-2022-30313 Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a … Safety Manager Firmware Mitigation only Fix from $1,9502022-07-28 MEDIUM 5.3 CVE-2022-36884 The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to… Git after 4.11.3 Fix from $1,6002022-07-27 HIGH 7.5 CVE-2022-30276 The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for inter… Moscad Ip Gateway Firmware Mitigation only Fix from $1,9502022-07-26 CRITICAL 9.1 CVE-2022-36129 HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that coul… Vault after 1.10.4 Fix from $2,3002022-07-26 CRITICAL 9.1 CVE-2022-29951 JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP… Pc10g Cpu Tcc 6353 Firmware Mitigation only Fix from $2,3002022-07-26 CRITICAL 9.1 CVE-2022-29952 Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP,… Bently Nevada 3701\/40 Firmware 4.1+ Fix from $2,3002022-07-26 HIGH 7.8 CVE-2022-29957 The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wid… Deltav Distributed Control System after 2022-04-29 Fix from $1,9502022-07-26 HIGH 7.8 CVE-2022-35871EPSS 39% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).… Ignition Mitigation only Fix from $1,9502022-07-25 HIGH 7.5 CVE-2022-2138EPSS 11% The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary … Iview 5.7.04.6469+ Fix from $1,9502022-07-22 MEDIUM 5.3 CVE-2021-36200 Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions … Metasys Application And Data Server 10.1.6 / 11.0.2+ Fix from $1,6002022-07-22 CRITICAL 9.8 CVE-2022-34767 Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows … All Wr0500ac Firmware Mitigation only Fix from $2,3002022-07-21 CRITICAL 9.8 CVE-2022-20857 Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta… Nexus Dashboard 2.2+ Fix from $2,3002022-07-21 CRITICAL 9.8 CVE-2022-20858 Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta… Nexus Dashboard 2.2+ Fix from $2,3002022-07-21 HIGH 8.8 CVE-2022-20861 Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta… Nexus Dashboard 2.2+ Fix from $1,9502022-07-21 CRITICAL 9.8 CVE-2022-2141 SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication. Mv720 Firmware Mitigation only Fix from $2,3002022-07-20 HIGH 7.8 CVE-2022-28809 An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with a… Drawings Sdk 2023.3+ Fix from $1,9502022-07-17 MEDIUM 6.5 CVE-2022-31260 In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k v… Resourcespace 9.8+ Fix from $1,6002022-07-17 HIGH 7.5 CVE-2021-34538 Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was… Hive 3.1.3+ Fix from $1,9502022-07-16 HIGH 7.5 CVE-2022-28771 Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http re… Business One License Service Api Mitigation only Fix from $1,9502022-07-12 CRITICAL 9.1 CVE-2021-44222 A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not p… Simatic Easie Core Package 22.00+ Fix from $2,3002022-07-12 HIGH 7.5 CVE-2022-33138 A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < … Simatic Mv540 H Firmware 3.3+ Fix from $1,9502022-07-12 MEDIUM 6.4 CVE-2022-23719 PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker wi… Pingid Integration For Windows Login 2.8+ Fix from $1,6002022-06-30