Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-35733
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1…
Udr Ja1004 Firmware
after 2.0.20.13
CRITICAL 9.8
CVE-2022-34858
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Oauth 2.0 Client For Sso
1.11.4+
MEDIUM 5.3
CVE-2022-2552EPSS 11%
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as serve…
Duplicator
1.4.7.1+
HIGH 7.5
CVE-2022-37062
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory…
Flir Ax8 Firmware
after 1.46.16
CRITICAL 9.1
CVE-2022-35122
An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information i…
Gw1100 Firmware
after 2.1.5
CRITICAL 9.8
CVE-2022-2765
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown f…
Company Website Cms
No fix yet
CRITICAL 9.8
CVE-2022-2242
The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write …
Systemsoftware V\/kss
8.6.5+
CRITICAL 9.8
CVE-2022-35865
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re…
Track It\!
Patch available
HIGH 7.5
CVE-2022-30313
Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a …
Safety Manager Firmware
Mitigation only
MEDIUM 5.3
CVE-2022-36884
The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to…
Git
after 4.11.3
HIGH 7.5
CVE-2022-30276
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for inter…
Moscad Ip Gateway Firmware
Mitigation only
CRITICAL 9.1
CVE-2022-36129
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that coul…
Vault
after 1.10.4
CRITICAL 9.1
CVE-2022-29951
JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP…
Pc10g Cpu Tcc 6353 Firmware
Mitigation only
CRITICAL 9.1
CVE-2022-29952
Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP,…
Bently Nevada 3701\/40 Firmware
4.1+
HIGH 7.8
CVE-2022-29957
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wid…
Deltav Distributed Control System
after 2022-04-29
HIGH 7.8
CVE-2022-35871EPSS 39%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114).…
Ignition
Mitigation only
HIGH 7.5
CVE-2022-2138EPSS 11%
The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary …
Iview
5.7.04.6469+
MEDIUM 5.3
CVE-2021-36200
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions …
Metasys Application And Data Server
10.1.6 / 11.0.2+
CRITICAL 9.8
CVE-2022-34767
Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows …
All Wr0500ac Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-20857
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…
Nexus Dashboard
2.2+
CRITICAL 9.8
CVE-2022-20858
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…
Nexus Dashboard
2.2+
HIGH 8.8
CVE-2022-20861
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload conta…
Nexus Dashboard
2.2+
CRITICAL 9.8
CVE-2022-2141
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
Mv720 Firmware
Mitigation only
HIGH 7.8
CVE-2022-28809
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading a DWG file with a…
Drawings Sdk
2023.3+
MEDIUM 6.5
CVE-2022-31260
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k v…
Resourcespace
9.8+
HIGH 7.5
CVE-2021-34538
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was…
Hive
3.1.3+
HIGH 7.5
CVE-2022-28771
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http re…
Business One License Service Api
Mitigation only
CRITICAL 9.1
CVE-2021-44222
A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not p…
Simatic Easie Core Package
22.00+
HIGH 7.5
CVE-2022-33138
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < …
Simatic Mv540 H Firmware
3.3+
MEDIUM 6.4
CVE-2022-23719
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker wi…
Pingid Integration For Windows Login
2.8+