Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.1 CVE-2022-1521 LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data. Local Run Manager after 3.1 Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2021-26637 There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized… Sihas Sgw 300 Firmware Mitigation only Fix from $2,3002022-06-23 HIGH 7.5 CVE-2022-21952 A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote atta… Manager Server 4.1.46 / 4.2.37+ Fix from $1,9502022-06-22 CRITICAL 9.8 CVE-2022-24562EPSS 53% In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the ent… Iotransfer Mitigation only Fix from $2,3002022-06-16 CRITICAL 9.8 CVE-2021-41418 AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights. Ariang after 1.2.2 Fix from $2,3002022-06-15 HIGH 7.5 CVE-2022-32157 Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to updat… Splunk 9.0+ Fix from $1,9502022-06-15 HIGH 7.5 CVE-2022-32557 An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers. Couchbase Server 7.0.4+ Fix from $1,9502022-06-14 HIGH 7.2 CVE-2022-30229 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated acce… Sicam Gridedge Essential 2.6.6+ Fix from $1,9502022-06-14 CRITICAL 9.8 CVE-2022-30230 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated acce… Sicam Gridedge Essential 2.6.6+ Fix from $2,3002022-06-14 CRITICAL 9.8 CVE-2022-32251 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). There is a missing authentication verification for a resou… Sinema Remote Connect Server 3.1+ Fix from $2,3002022-06-14 CRITICAL 9.1 CVE-2022-29226 Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validati… Envoy 1.22.1+ Fix from $2,3002022-06-09 MEDIUM 5.3 CVE-2022-1598EPSS 5% The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unau… Wpqa Builder 5.4+ Fix from $1,6002022-06-08 HIGH 7.5 CVE-2021-42893 In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg. Ex1200t Firmware No fix yet Fix from $1,9502022-06-03 HIGH 7.5 CVE-2021-42891 In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization. Ex1200t Firmware No fix yet Fix from $1,9502022-06-03 HIGH 7.5 CVE-2021-42889 In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization. Ex1200t Firmware No fix yet Fix from $1,9502022-06-03 MEDIUM 6.5 CVE-2022-31461 Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message. Meeting Owl Pro Firmware 5.4.2.3+ Fix from $1,6002022-06-02 MEDIUM 5.3 CVE-2022-26971 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This uplo… Control Room Management Suite 3.14.1+ Fix from $1,6002022-06-02 MEDIUM 5.5 CVE-2022-31022 Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP … Bleve Patch available Fix from $1,6002022-06-01 HIGH 8.1 CVE-2022-22576 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections witho… Curl 7.83.0+ Fix from $1,9502022-05-26 HIGH 7.5 CVE-2022-26067 An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.01… Oas Platform No fix yet Fix from $1,9502022-05-25 CRITICAL 9.8 CVE-2022-26082EPSS 20% A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A special… Oas Platform No fix yet Fix from $2,3002022-05-25 HIGH 7.5 CVE-2022-26303 An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Software OAS Platform V16.00.0112. A… Oas Platform No fix yet Fix from $1,9502022-05-25 CRITICAL 9.4 CVE-2022-26833EPSS 38% An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-craft… Oas Platform No fix yet Fix from $2,3002022-05-25 HIGH 7.5 CVE-2022-27169 An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Software OAS Platform V16.00.0112.… Oas Platform No fix yet Fix from $1,9502022-05-25 HIGH 7.5 CVE-2022-26026 A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software OAS Platform V16.00.0112. A s… Oas Platform No fix yet Fix from $1,9502022-05-25 HIGH 7.5 CVE-2022-26043 An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.011… Oas Platform No fix yet Fix from $1,9502022-05-25 MEDIUM 6.8 CVE-2022-29402 TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allows attackers to connect to the… Tl Wr840n Firmware No fix yet Fix from $1,6002022-05-25 MEDIUM 6.8 CVE-2022-22309 The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability can be more critical if the s… Power System S922 Firmware 860.b0 / 940.60+ Fix from $1,6002022-05-24 CRITICAL 9.8 CVE-2022-28660 The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version… Grafana 1.2.1+ Fix from $2,3002022-05-20 MEDIUM 6.5 CVE-2022-29877 A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM… 7kg8500 0aa00 0aa0 Firmware 3.00+ Fix from $1,6002022-05-20