Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Cf Wr610n Firmware MEDIUM 5.4
CVE-2022-45724

Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthent…

No fix yet
Fix from $1,600 2023-02-13
Datahub HIGH 8.1
CVE-2023-25559

DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata…

Fix: 0.8.45+
Fix from $1,950 2023-02-11
Android MEDIUM 5.5
CVE-2023-21437

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via…

Mitigation only
Fix from $1,600 2023-02-09
Android MEDIUM 5.5
CVE-2023-21425

Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.

Mitigation only
Fix from $1,600 2023-02-09
Android HIGH 7.5
CVE-2023-21419

An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain co…

Mitigation only
Fix from $1,950 2023-02-09
Emui HIGH 7.5
CVE-2022-48294

The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality.

No fix yet
Fix from $1,950 2023-02-09
Couchbase Server HIGH 8.1
CVE-2022-42951

An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbas…

Fix: 6.6.6 / 7.0.5+
Fix from $1,950 2023-02-06
Jira Service Management CRITICAL 9.1
CVE-2023-22501EPSS 16%

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user…

Fix: 5.3.3 / 5.4.2+
Fix from $2,300 2023-02-01
Mura Cms CRITICAL 9.8
CVE-2022-47003

A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

Fix: 10.0.580+
Fix from $2,300 2023-02-01
Portfoliocms HIGH 7.5
CVE-2020-20402

Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.

No fix yet
Fix from $1,950 2023-01-31
Storage Plug In HIGH 8.8
CVE-2022-4041

Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escal…

Mitigation only
Fix from $1,950 2023-01-31
Storage Plug In HIGH 8.8
CVE-2022-4441

Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escal…

Mitigation only
Fix from $1,950 2023-01-31
Storage Security Software HIGH 7.8
CVE-2022-30421

Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive information to be obtained via(lo…

No fix yet
Fix from $1,950 2023-01-31
5500ac2 Firmware CRITICAL 9.8
CVE-2022-32514

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affe…

Fix: 1.11.0+
Fix from $2,300 2023-01-30
Iotdb HIGH 7.5
CVE-2023-24830

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before…

Fix: 0.13.3+
Fix from $1,950 2023-01-30
A830r Firmware CRITICAL 9.8
CVE-2022-48066

An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.

No fix yet
Fix from $2,300 2023-01-27
Opensearch HIGH 8.8
CVE-2023-23612

OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (Id…

Fix: 1.3.8 / 2.5.0+
Fix from $1,950 2023-01-26
Android MEDIUM 6.8
CVE-2023-20924

In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to local escalation of privilege w…

Mitigation only
Fix from $1,600 2023-01-26
Server HIGH 7.5
CVE-2021-43444

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default U…

Fix: after 7.0.0.49
Fix from $1,950 2023-01-23
Server CRITICAL 9.8
CVE-2021-43445

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONL…

Fix: after 7.0.0.49
Fix from $2,300 2023-01-23
R310 Firmware CRITICAL 9.1
CVE-2020-22657

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10…

Fix: 3.6.2.0.795+
Fix from $2,300 2023-01-20
Manageengine Servicedesk Plus Msp CRITICAL 9.1
CVE-2023-22964

Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.

Mitigation only
Fix from $2,300 2023-01-20
Conprosys Hmi System MEDIUM 5.3
CVE-2023-22334

Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authent…

Fix: after 3.4.5
Fix from $1,600 2023-01-20
Opentext Extended Ecm HIGH 8.8
CVE-2022-45922

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd coo…

Fix: after 22.1
Fix from $1,950 2023-01-18
Zowe Api Mediation Layer MEDIUM 5.3
CVE-2021-4314

It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happ…

Fix: 1.19.0+
Fix from $1,600 2023-01-18
Weblogic Server HIGH 7.5
CVE-2023-21841

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Patch available
Fix from $1,950 2023-01-18
M Filter MEDIUM 5.3
CVE-2023-22278

m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass auth…

Fix: 4.87r04 / 5.70r01+
Fix from $1,600 2023-01-17
Tl Sg105pe Firmware CRITICAL 9.8
CVE-2023-22303

TP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerability. Under the certain condit…

Mitigation only
Fix from $2,300 2023-01-17
Phpmyfaq CRITICAL 9.8
CVE-2023-0311

Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

Fix: 3.1.10+
Fix from $2,300 2023-01-15
Netdata CRITICAL 9.1
CVE-2023-22497

Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHI…

Fix: 1.37.0+
Fix from $2,300 2023-01-14