Show filters
612 Total Results
Displaying 111-120 of 612
Sort by:
Attacker Value
Unknown

CVE-2022-28771

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.
Attacker Value
Unknown

CVE-2022-33138

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S (All versions < V3.3), SIMATIC MV550 H (All versions < V3.3), SIMATIC MV550 S (All versions < V3.3), SIMATIC MV560 U (All versions < V3.3), SIMATIC MV560 X (All versions < V3.3). Affected devices do not perform authentication for several web API endpoints. This could allow an unauthenticated remote attacker to read and download data from the device.
Attacker Value
Unknown

CVE-2021-44222

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages to the service and thereby issue arbitrary requests in the affected system.
Attacker Value
Unknown

CVE-2022-23719

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack vectors. A successful attack can lead to code executed as SYSTEM by the PingID Windows Login application, or even a denial of service for offline security key authentication.
Attacker Value
Unknown

CVE-2022-31266

Disclosure Date: June 29, 2022 (last updated February 24, 2025)
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.
Attacker Value
Unknown

CVE-2022-29270

Disclosure Date: June 29, 2022 (last updated February 24, 2025)
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
Attacker Value
Unknown

CVE-2022-2138

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of-service condition.
Attacker Value
Unknown

CVE-2022-1521

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.
Attacker Value
Unknown

CVE-2021-26637

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
Attacker Value
Unknown

CVE-2022-21952

Disclosure Date: June 20, 2022 (last updated February 23, 2025)
A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37.