Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 5.3 CVE-2022-29881 A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special … 7kg8500 0aa00 0aa0 Firmware 3.00+ Fix from $1,6002022-05-20 MEDIUM 5.3 CVE-2022-29883 A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the… 7kg8500 0aa00 0aa0 Firmware 3.00+ Fix from $1,6002022-05-20 MEDIUM 5.9 CVE-2022-26925 KEVEPSS 11% Windows LSA Spoofing Vulnerability Windows 10 1507 10.0.10240.19297 / 10.0.14393.5125+ Fix from $1,6002022-05-10 MEDIUM 5.3 CVE-2022-0424 The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated … Popup 1.10.9+ Fix from $1,6002022-05-09 MEDIUM 6.5 CVE-2022-27495 On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions… Nginx Service Mesh Mitigation only Fix from $1,6002022-05-05 CRITICAL 9.8 CVE-2022-1388 KEVEPSS 100% On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5… Big Ip Access Policy Manager 13.1.5 / 14.1.4.6+ Fix from $2,3002022-05-05 CRITICAL 9.8 CVE-2022-1300 Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unau… Trutops Boost after 22.05 Fix from $2,3002022-05-02 HIGH 7.8 CVE-2022-29934 USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is… Oracle Optimization No fix yet Fix from $1,9502022-04-29 HIGH 7.5 CVE-2022-24935 Lexmark products through 2022-02-10 have Incorrect Access Control. Lexmark Firmware after 2022-02-10 Fix from $1,9502022-04-28 CRITICAL 9.8 CVE-2022-28719 Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the sys… Assetview 13.2.0+ Fix from $2,3002022-04-28 CRITICAL 9.1 CVE-2022-27332 An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow… Zammad 5.1.0+ Fix from $2,3002022-04-27 HIGH 8.1 CVE-2021-25094EPSS 83% The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompre… Tatsu 3.3.12+ Fix from $1,9502022-04-25 CRITICAL 9.8 CVE-2022-0992 The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use… Security Optimizer 1.2.6+ Fix from $2,3002022-04-19 CRITICAL 9.8 CVE-2022-0993EPSS 7% The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use… Siteground Security after 1.2.5 Fix from $2,3002022-04-19 MEDIUM 5.3 CVE-2022-0140 The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the… Visual Form Builder 3.0.6+ Fix from $1,6002022-04-12 MEDIUM 6.5 CVE-2022-0878 Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of… Combined Charging System Firmware after 2.0 Fix from $1,6002022-04-12 CRITICAL 9.8 CVE-2022-24829 Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authenticati… Garden 0.12.39+ Fix from $2,3002022-04-11 MEDIUM 5.3 CVE-2022-24820 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages… Xwiki 12.10.11 / 13.4.4+ Fix from $1,6002022-04-08 HIGH 8.0 CVE-2021-43483 An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update… Kaon Cg3000 Firmware No fix yet Fix from $1,9502022-04-08 HIGH 8.8 CVE-2020-27376 Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication. Icheck Connect Bp Monitor Bp Testing 118 Firmware Mitigation only Fix from $1,9502022-04-07 HIGH 7.3 CVE-2022-1248 A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/… Sap Information System No fix yet Fix from $1,9502022-04-06 MEDIUM 5.3 CVE-2022-25245 Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. Manageengine Servicedesk Plus after 12.0 Fix from $1,6002022-04-05 CRITICAL 9.8 CVE-2021-33008 AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity. System Platform 2020+ Fix from $2,3002022-04-04 MEDIUM 6.5 CVE-2022-0922 The software does not perform any authentication for critical system functionality. E Alert Firmware 2.7+ Fix from $1,6002022-04-01 MEDIUM 5.3 CVE-2020-14479 Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to q… Ignition 7.9.14+ Fix from $1,6002022-04-01 HIGH 8.8 CVE-2022-25008 totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism. Ex300 V2 Firmware No fix yet Fix from $1,9502022-03-30 MEDIUM 6.5 CVE-2021-46006EPSS 5% In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure m… A3100r Firmware No fix yet Fix from $1,6002022-03-30 CRITICAL 9.8 CVE-2021-46009EPSS 13% In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set… A3100r Firmware Mitigation only Fix from $2,3002022-03-30 HIGH 8.0 CVE-2021-3589 An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access host… Satellite 7.1.0+ Fix from $1,9502022-03-23 HIGH 7.5 CVE-2022-23345 BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control. Bigant Server No fix yet Fix from $1,9502022-03-21