Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 7.2 CVE-2021-44255 Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup fil… Motioneye 0.42.1 / 20200606+ Fix from $1,9502022-01-31 MEDIUM 5.5 CVE-2021-26264 A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service cond… Deltav Workstation No fix yet Fix from $1,6002022-01-28 MEDIUM 6.5 CVE-2021-34870 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR XR1000 1.0.0.52_1.0.38 ro… Xr1000 Patch available Fix from $1,6002022-01-25 CRITICAL 9.1 CVE-2022-23944EPSS 79% User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Patch available Fix from $2,3002022-01-25 HIGH 7.5 CVE-2022-23945 Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. Shenyu Patch available Fix from $1,9502022-01-25 MEDIUM 5.3 CVE-2021-33843 Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this function… Agilia Sp Mc Wifi Firmware Mitigation only Fix from $1,6002022-01-21 HIGH 7.8 CVE-2022-23220 USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g.… Usbview 2.2+ Fix from $1,9502022-01-21 HIGH 7.8 CVE-2021-23843 The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a pa… Amc2 Firmware 4.9.1+ Fix from $1,9502022-01-19 CRITICAL 9.8 CVE-2021-35587 KEVEPSS 96% Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 1… Access Manager Mitigation only Fix from $2,3002022-01-19 CRITICAL 9.1 CVE-2021-28506 An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially… Eos after 4.26.2f Fix from $2,3002022-01-14 CRITICAL 9.8 CVE-2022-23227 KEVEPSS 49% NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because … Nvrmini2 Firmware after 3.11.0 Fix from $2,3002022-01-14 MEDIUM 5.3 CVE-2021-43974 An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the serv… Itil No fix yet Fix from $1,6002022-01-11 CRITICAL 9.8 CVE-2021-43832 Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. Thi… Spinnaker 1.25.8 / 1.26.7+ Fix from $2,3002022-01-04 MEDIUM 6.5 CVE-2021-43333 The Datalogic DXU service on (for example) DL-Axist devices does not require authentication for configuration changes or disclosure of configuration … Dxu after 2.1.3 Fix from $1,6002022-01-01 MEDIUM 6.8 CVE-2021-20161 Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to… Tew 827dru Firmware Mitigation only Fix from $1,6002021-12-30 MEDIUM 5.3 CVE-2021-20150EPSS 40% Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and… Tew 827dru Firmware Mitigation only Fix from $1,6002021-12-30 MEDIUM 6.5 CVE-2021-20152 Trendnet AC2600 TEW-827DRU version 2.08B01 lacks proper authentication to the bittorrent functionality. If enabled, anyone is able to visit and modif… Tew 827dru Firmware Mitigation only Fix from $1,6002021-12-30 CRITICAL 9.8 CVE-2021-20158EPSS 11% Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to … Tew 827dru Firmware Mitigation only Fix from $2,3002021-12-30 CRITICAL 9.8 CVE-2021-45232EPSS 86% In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all… Apisix Dashboard 2.10.1+ Fix from $2,3002021-12-27 HIGH 8.1 CVE-2021-36780 A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica in… Longhorn 1.1.3 / 1.2.3+ Fix from $1,9502021-12-17 CRITICAL 9.6 CVE-2021-36779 A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to execute any binary present in the… Longhorn 1.1.3 / 1.2.3+ Fix from $2,3002021-12-17 CRITICAL 9.8 CVE-2021-36888EPSS 7% Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6… Image Hover Effects 9.6.1+ Fix from $2,3002021-12-15 CRITICAL 9.8 CVE-2021-22279 A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot contro… Omnicore C30 Firmware 7.3.2+ Fix from $2,3002021-12-13 CRITICAL 9.8 CVE-2021-44152EPSS 59% An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthentica… Reprise License Manager 15.1+ Fix from $2,3002021-12-13 HIGH 7.5 CVE-2021-34543 The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administr… Solar Log 500 Firmware after 2.8.1 Fix from $1,9502021-12-07 HIGH 7.5 CVE-2021-38147EPSS 53% Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive inform… Holmes No fix yet Fix from $1,9502021-11-29 HIGH 7.5 CVE-2021-38283 Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a pre… Holmes No fix yet Fix from $1,9502021-11-29 CRITICAL 9.8 CVE-2021-44077 KEVEPSS 93% Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentic… Manageengine Servicedesk Plus 10.5 / 11.0+ Fix from $2,3002021-11-29 CRITICAL 9.8 CVE-2021-42783 Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to… Dwr 932c E1 Firmware after 1.0.0.4 Fix from $2,3002021-11-23 CRITICAL 9.1 CVE-2021-39233 In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any … Ozone 1.2.0+ Fix from $2,3002021-11-19