Vulnerability index

Browse CVEs

2,904 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
CRITICAL 9.8 CVE-2021-30167 The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend … P2r8852e2 Firmware 7.1.94.8908+ Fix from $2,3002021-04-28 HIGH 7.5 CVE-2021-29442EPSS 65% Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsCont… Nacos 1.4.1+ Fix from $1,9502021-04-27 HIGH 7.5 CVE-2020-17517 The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allo… Ozone 1.1.0+ Fix from $1,9502021-04-27 HIGH 7.5 CVE-2020-15078 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with defe… Openvpn 2.4.11 / 2.5.2+ Fix from $1,9502021-04-26 CRITICAL 9.8 CVE-2021-20697 Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an au… Dap 1880ac Firmware after 1.21 Fix from $2,3002021-04-26 HIGH 7.5 CVE-2021-20990 In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API… Home Center 2 Firmware after 4.600 Fix from $1,9502021-04-19 MEDIUM 5.3 CVE-2021-24219 The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin be… Focusblog 2.0.0+ Fix from $1,6002021-04-12 HIGH 7.2 CVE-2021-30462 VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/… Vesta Control Panel after 0.9.8-24 Fix from $1,9502021-04-08 MEDIUM 5.9 CVE-2021-28124 A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Mi… Cohesity Dataplatform after 6.5.1b Fix from $1,6002021-04-02 HIGH 7.5 CVE-2021-22997 On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ HA ElasticSearch service does not implement any form of authentication for the clustering transp… Big Iq Centralized Management 8.0.0+ Fix from $1,9502021-03-31 HIGH 7.5 CVE-2021-22995 On all 7.x and 6.x versions (fixed in 8.0.0), BIG-IQ high availability (HA) when using a Quorum device for automatic failover does not implement any … Big Iq Centralized Management after 7.1.0 Fix from $1,9502021-03-31 CRITICAL 9.8 CVE-2020-25218 Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. Grp2612 Firmware Mitigation only Fix from $2,3002021-03-29 HIGH 7.5 CVE-2021-28148 One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without … Grafana 6.7.6 / 7.3.10+ Fix from $1,9502021-03-22 CRITICAL 9.1 CVE-2020-28899 The Web CGI Script on ZyXEL LTE4506-M606 V1.00(ABDO.2)C0 devices does not require authentication, which allows remote unauthenticated attackers (via … Lte4506 M606 Firmware Mitigation only Fix from $2,3002021-03-16 HIGH 7.1 CVE-2020-35226 NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write re… Gs116e Firmware Mitigation only Fix from $1,9502021-03-10 HIGH 7.5 CVE-2020-19419 Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the admini… Smart Wireless Gateway 1420 Firmware No fix yet Fix from $1,9502021-03-10 CRITICAL 9.8 CVE-2021-28122 A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a cr… Open5gs after 2.2.0 Fix from $2,3002021-03-10 HIGH 7.8 CVE-2020-27225 In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, all… Platform after 4.18 Fix from $1,9502021-03-09 MEDIUM 6.8 CVE-2021-20262 A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an … Keycloak Mitigation only Fix from $1,6002021-03-09 HIGH 8.8 CVE-2021-27255 This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentica… Br200 Firmware 1.0.0.134 / 1.0.1.60+ Fix from $1,9502021-03-05 CRITICAL 9.1 CVE-2021-26705 An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentica… Catdv after 9.2 Fix from $2,3002021-03-05 HIGH 8.2 CVE-2021-27963 SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous user can send a POST request t… Sonlogger 6.4.1+ Fix from $1,9502021-03-05 CRITICAL 9.8 CVE-2021-27215 An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Us… Genuagate after 10.1 Fix from $2,3002021-03-03 HIGH 7.5 CVE-2019-25020 An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can retrieve the administrative … Secure Vote No fix yet Fix from $1,9502021-02-27 CRITICAL 9.8 CVE-2019-11684 Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limi… Video Recording Manager 3.71.0034 / 3.80.0039+ Fix from $2,3002021-02-26 CRITICAL 9.8 CVE-2021-1393 Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level… Application Services Engine 1.1+ Fix from $2,3002021-02-24 MEDIUM 6.5 CVE-2021-1396 Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level… Application Services Engine 1.1+ Fix from $1,6002021-02-24 HIGH 7.5 CVE-2021-20662 Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to alter the setting information w… Sv Cpt Mc310 Firmware 6.5+ Fix from $1,9502021-02-24 HIGH 8.1 CVE-2021-20198 A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Pl… Openshift Installer 0.9.0-master.0.20210125200451-95101da940b0+ Fix from $1,9502021-02-23 HIGH 8.8 CVE-2020-36245 GramAddict through 1.2.3 allows remote attackers to execute arbitrary code because of use of UIAutomator2 and ATX-Agent. The attacker must be able to… Gramaddict after 1.2.3 Fix from $1,9502021-02-17