Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2022-29881
A vulnerability has been identified in SICAM T (All versions < V3.0). The web based management interface of affected devices does not employ special …
7kg8500 0aa00 0aa0 Firmware
3.00+
MEDIUM 5.3
CVE-2022-29883
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the…
7kg8500 0aa00 0aa0 Firmware
3.00+
MEDIUM 5.9
CVE-2022-26925 KEVEPSS 11%
Windows LSA Spoofing Vulnerability
Windows 10 1507
10.0.10240.19297 / 10.0.14393.5125+
MEDIUM 5.3
CVE-2022-0424
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated …
Popup
1.10.9+
MEDIUM 6.5
CVE-2022-27495
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions…
Nginx Service Mesh
Mitigation only
CRITICAL 9.8
CVE-2022-1388 KEVEPSS 100%
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5…
Big Ip Access Policy Manager
13.1.5 / 14.1.4.6+
CRITICAL 9.8
CVE-2022-1300
Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unau…
Trutops Boost
after 22.05
HIGH 7.8
CVE-2022-29934
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is…
Oracle Optimization
No fix yet
HIGH 7.5
CVE-2022-24935
Lexmark products through 2022-02-10 have Incorrect Access Control.
Lexmark Firmware
after 2022-02-10
CRITICAL 9.8
CVE-2022-28719
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the sys…
Assetview
13.2.0+
CRITICAL 9.1
CVE-2022-27332
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow…
Zammad
5.1.0+
HIGH 8.1
CVE-2021-25094EPSS 83%
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompre…
Tatsu
3.3.12+
CRITICAL 9.8
CVE-2022-0992
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use…
Security Optimizer
1.2.6+
CRITICAL 9.8
CVE-2022-0993EPSS 7%
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative use…
Siteground Security
after 1.2.5
MEDIUM 5.3
CVE-2022-0140
The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing unauthenticated users to see the…
Visual Form Builder
3.0.6+
MEDIUM 6.5
CVE-2022-0878
Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important messages such as the State of…
Combined Charging System Firmware
after 2.0
CRITICAL 9.8
CVE-2022-24829
Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authenticati…
Garden
0.12.39+
MEDIUM 5.3
CVE-2022-24820
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages…
Xwiki
12.10.11 / 13.4.4+
HIGH 8.0
CVE-2021-43483
An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update…
Kaon Cg3000 Firmware
No fix yet
HIGH 8.8
CVE-2020-27376
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Missing Authentication.
Icheck Connect Bp Monitor Bp Testing 118 Firmware
Mitigation only
HIGH 7.3
CVE-2022-1248
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/…
Sap Information System
No fix yet
MEDIUM 5.3
CVE-2022-25245
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
Manageengine Servicedesk Plus
after 12.0
CRITICAL 9.8
CVE-2021-33008
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.
System Platform
2020+
MEDIUM 6.5
CVE-2022-0922
The software does not perform any authentication for critical system functionality.
E Alert Firmware
2.7+
MEDIUM 5.3
CVE-2020-14479
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to q…
Ignition
7.9.14+
HIGH 8.8
CVE-2022-25008
totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism.
Ex300 V2 Firmware
No fix yet
MEDIUM 6.5
CVE-2021-46006EPSS 5%
In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can configure m…
A3100r Firmware
No fix yet
CRITICAL 9.8
CVE-2021-46009EPSS 13%
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set…
A3100r Firmware
Mitigation only
HIGH 8.0
CVE-2021-3589
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access host…
Satellite
7.1.0+
HIGH 7.5
CVE-2022-23345
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
Bigant Server
No fix yet