Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2021-41266EPSS 48% Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are s… Minio Console 0.12.3+ Fix from $2,3002021-11-15 CRITICAL 9.8 CVE-2021-20136EPSS 10% ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthentica… Manageengine Log360 after 5.2 Fix from $2,3002021-11-01 MEDIUM 5.3 CVE-2021-33259 Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query hi… Dir 868lw Firmware No fix yet Fix from $1,6002021-10-31 MEDIUM 5.3 CVE-2021-41157 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.10.6+ Fix from $1,6002021-10-26 HIGH 7.5 CVE-2021-37624 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.10.7+ Fix from $1,9502021-10-25 HIGH 8.8 CVE-2021-42539 The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved … Wireless 1410 Gateway Firmware 4.7.94+ Fix from $1,9502021-10-22 CRITICAL 9.8 CVE-2021-38457 The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing … Versiondog 8.0.0+ Fix from $2,3002021-10-22 HIGH 8.1 CVE-2021-27395 A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 … Simatic Process Historian 2013 Mitigation only Fix from $1,9502021-10-12 MEDIUM 6.5 CVE-2021-41568 Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin b… Tad Web after 1.76 Fix from $1,6002021-10-08 CRITICAL 9.1 CVE-2021-41974 Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content o… Tad Book3 3.9+ Fix from $2,3002021-10-08 CRITICAL 9.1 CVE-2021-41975 TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the sy… Tadtools 3.2.2+ Fix from $2,3002021-10-08 MEDIUM 5.3 CVE-2021-41976 Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in t… Tad Uploader 3.5.4+ Fix from $1,6002021-10-08 HIGH 8.1 CVE-2021-35979 An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle attacks and does not perform auth… Realport after 4.8.488.0 Fix from $1,9502021-10-08 HIGH 7.5 CVE-2021-23858 Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can … Rexroth Indramotion Mlc L20 Firmware after 12 Fix from $1,9502021-10-04 CRITICAL 9.6 CVE-2021-3825 On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to… Liderahenk after 2.1.15 Fix from $2,3002021-10-01 HIGH 7.5 CVE-2021-41104 ESPHome is a system to control the ESP8266/ESP32. Anyone with web_server enabled and HTTP basic auth configured on version 2021.9.1 or older is vulne… Esphome Firmware 2021.9.2+ Fix from $1,9502021-09-28 HIGH 7.5 CVE-2021-22012 The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with networ… Cloud Foundation 5.0+ Fix from $1,9502021-09-23 MEDIUM 6.5 CVE-2021-37420 Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. Manageengine Admanager Plus 6.1+ Fix from $1,6002021-09-21 CRITICAL 9.8 CVE-2021-38412 Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require auth… Portserver Ts 16 Firmware Mitigation only Fix from $2,3002021-09-17 MEDIUM 5.3 CVE-2019-10941 A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative … Sinema Server 14.0+ Fix from $1,6002021-09-14 CRITICAL 9.8 CVE-2021-33543EPSS 82% Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user au… G Cam Ebc 2110 Firmware after 1.12.0.27 Fix from $2,3002021-09-13 CRITICAL 9.8 CVE-2021-28913 BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to validate the so called and har… Eibport Firmware 3.9.1+ Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-38540EPSS 81% The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint … Airflow 2.1.3+ Fix from $2,3002021-09-09 HIGH 8.1 CVE-2021-32800 Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextc… Nextcloud Server 20.0.12 / 21.0.4+ Fix from $1,9502021-09-07 CRITICAL 9.8 CVE-2021-37415 KEVEPSS 100% Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. Manageengine Servicedesk Plus Mitigation only Fix from $2,3002021-09-01 MEDIUM 5.3 CVE-2021-27668 HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3. Vault 1.6.3+ Fix from $1,6002021-08-31 HIGH 8.6 CVE-2021-33882 A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote attacker to reconfigure the de… Spacecom2 012u000062+ Fix from $1,9502021-08-25 HIGH 8.5 CVE-2021-39144 KEVEPSS 98% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has suffi… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 MEDIUM 5.4 CVE-2021-31868 Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feat… Nexpose 6.6.96+ Fix from $1,6002021-08-19 MEDIUM 5.3 CVE-2021-35936 If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server… Airflow 2.1.2+ Fix from $1,6002021-08-16