Vulnerability index

Browse CVEs

2,893 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
MEDIUM 6.5 CVE-2021-37697 tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access… Tmerc Cogs 3.0+ Fix from $1,6002021-08-11 MEDIUM 6.5 CVE-2021-37696 tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access… Tmerc Cogs 3.0+ Fix from $1,6002021-08-11 CRITICAL 9.8 CVE-2020-25563 In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTask… Sapphireims No fix yet Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2020-25566 In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not requ… Sapphireims No fix yet Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2021-37843 The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no othe… Saml Single Sign On 2.5.9 / 3.5.6+ Fix from $2,3002021-08-02 CRITICAL 9.8 CVE-2020-36239EPSS 47% Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.1… Jira Data Center 4.5.16 / 4.13.8+ Fix from $2,3002021-07-29 HIGH 7.5 CVE-2021-32794 ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code `POST /… Archisteamfarm 5.1.2.4+ Fix from $1,9502021-07-26 HIGH 7.2 CVE-2020-7389 Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by t… Syracuse 9.22.7.2 / 11.25.2.6+ Fix from $1,9502021-07-22 CRITICAL 9.8 CVE-2021-22772 A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 … T200i Firmware Mitigation only Fix from $2,3002021-07-21 MEDIUM 5.7 CVE-2021-22784EPSS 12% A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a… C Bus Toolkit 1.15.9+ Fix from $1,6002021-07-21 HIGH 7.5 CVE-2020-21934 An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed. Cx2 Firmware No fix yet Fix from $1,9502021-07-21 MEDIUM 5.3 CVE-2020-21936 An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSett… Cx2 Firmware No fix yet Fix from $1,6002021-07-21 CRITICAL 9.8 CVE-2021-36124 An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive res… Sharecare Mitigation only Fix from $2,3002021-07-13 CRITICAL 9.8 CVE-2021-28809EPSS 16% An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attack… Hybrid Backup Sync 3.0.210506 / 3.0.210507+ Fix from $2,3002021-07-08 HIGH 7.5 CVE-2021-20474 IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity o… Guardium Data Encryption Patch available Fix from $1,9502021-07-07 CRITICAL 9.8 CVE-2021-33221EPSS 56% An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints. Ruckus Iot Controller after 1.7.1.0 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-34621EPSS 69% A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it … Profilepress after 3.1.3 Fix from $2,3002021-07-07 MEDIUM 5.4 CVE-2021-20107 There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS… Optima Eaf 100 Firmware No fix yet Fix from $1,6002021-06-30 HIGH 7.5 CVE-2021-35941EPSS 13% Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory re… Wd My Book Live Firmware No fix yet Fix from $1,9502021-06-29 CRITICAL 9.8 CVE-2021-31337 The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote … Sinamics Sl150 Firmware Mitigation only Fix from $2,3002021-06-28 CRITICAL 9.8 CVE-2021-33346 There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the … Dsl 2888a Firmware No fix yet Fix from $2,3002021-06-24 HIGH 7.4 CVE-2021-32700 Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha… Ballerina 1.2.14+ Fix from $1,9502021-06-22 MEDIUM 5.3 CVE-2020-20472 White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication oper… White Shark Systems No fix yet Fix from $1,6002021-06-21 CRITICAL 9.8 CVE-2021-32930EPSS 8% The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute ar… Iview 5.7.03.6182+ Fix from $2,3002021-06-11 CRITICAL 9.1 CVE-2021-23847 A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or chang… Cpp6 Firmware 7.80.0129+ Fix from $2,3002021-06-09 MEDIUM 6.8 CVE-2021-26928 BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for e… Bird after 2.0.7 Fix from $1,6002021-06-04 MEDIUM 6.8 CVE-2021-22316 There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby … Emui Mitigation only Fix from $1,6002021-06-03 HIGH 7.5 CVE-2021-22322 There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair … Emui Mitigation only Fix from $1,9502021-06-03 MEDIUM 5.4 CVE-2020-25634 A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa… 3scale 2.10.0+ Fix from $1,6002021-05-26 CRITICAL 9.8 CVE-2021-21986EPSS 13% The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Li… Vcenter Server 3.10.2.1 / 4.2.1+ Fix from $2,3002021-05-26