Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Keycloak MEDIUM 6.5
CVE-2023-0105

A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker …

Mitigation only
Fix from $1,600 2023-01-13
Trufusion Enterprise HIGH 7.5
CVE-2022-25027

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages…

Fix: 7.9.5.1+
Fix from $1,950 2023-01-12
Bv 10 Firmware CRITICAL 9.8
CVE-2022-39184

EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.

Mitigation only
Fix from $2,300 2023-01-12
Nf20 Firmware HIGH 7.5
CVE-2022-4874EPSS 11%

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static …

No fix yet
Fix from $1,950 2023-01-11
Rt Ax82u Firmware HIGH 8.1
CVE-2022-35401EPSS 21%

An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-craft…

No fix yet
Fix from $1,950 2023-01-10
Openharmony HIGH 7.8
CVE-2023-0035

softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows a…

Fix: after 3.0.5
Fix from $1,950 2023-01-09
Openharmony HIGH 7.8
CVE-2023-0036

platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA …

Fix: after 3.0.5
Fix from $1,950 2023-01-09
Event Management System CRITICAL 9.8
CVE-2022-1101

A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown proces…

Mitigation only
Fix from $2,300 2023-01-07
Collabcal CRITICAL 9.8
CVE-2014-125060

A vulnerability, which was classified as critical, was found in holdennb CollabCal. Affected is the function handleGet of the file calenderServer.cpp…

Fix: 2014-12-09+
Fix from $2,300 2023-01-07
Emui MEDIUM 6.5
CVE-2022-47974

The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth pro…

Fix: 2.0+
Fix from $1,600 2023-01-06
Emui HIGH 7.5
CVE-2022-47976

The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerab…

Fix: 2.0+
Fix from $1,950 2023-01-06
Foxman Un CRITICAL 9.8
CVE-2021-40342

In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensi…

Mitigation only
Fix from $2,300 2023-01-05
Aruba Edgeconnect Enterprise Orchestrator MEDIUM 6.5
CVE-2022-43528

Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code…

Fix: after 9.2.1.40179
Fix from $1,600 2023-01-05
A\+hrd CRITICAL 9.8
CVE-2022-39042

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication …

Mitigation only
Fix from $2,300 2023-01-03
Sasl CRITICAL 9.8
CVE-2022-48195

An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises suppor…

Mitigation only
Fix from $2,300 2022-12-31
Alpine MEDIUM 5.4
CVE-2022-23554

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the r…

Fix: 1.10.4+
Fix from $1,600 2022-12-28
Hota Fara B19 Firmware MEDIUM 6.5
CVE-2022-41579

There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect…

Mitigation only
Fix from $1,600 2022-12-28
Authentik MEDIUM 6.4
CVE-2022-46172

authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, and 2022.11.4, any authenticate…

Fix: 2022.10.4 / 2022.11.4+
Fix from $1,600 2022-12-28
Authentik HIGH 8.8
CVE-2022-23555

authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Imp…

Fix: 2022.10.4 / 2022.11.4+
Fix from $1,950 2022-12-28
Golang Nanoauth CRITICAL 9.1
CVE-2020-36569

Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063…

Fix: after 2020-01-31
Fix from $2,300 2022-12-27
Studio 5000 Logix Emulate HIGH 7.8
CVE-2022-3156

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on ce…

Fix: 34.00+
Fix from $1,950 2022-12-27
Rdiffweb HIGH 7.2
CVE-2022-4722

Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.

Fix: 2.5.5+
Fix from $1,950 2022-12-27
Airlink Mobility Manager CRITICAL 9.8
CVE-2020-11101

Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with a…

Fix: 2.17+
Fix from $2,300 2022-12-26
Kyverno HIGH 8.1
CVE-2022-47633

An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to …

Patch available
Fix from $1,950 2022-12-23
Firefox MEDIUM 6.5
CVE-2022-46875

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This…

Fix: 102.6 / 108.0+
Fix from $1,600 2022-12-22
Security Verify Governance MEDIUM 5.3
CVE-2022-35646

IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's acc…

Patch available
Fix from $1,600 2022-12-22
Codeigniter CRITICAL 9.8
CVE-2022-46170

CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin page…

Fix: 4.2.11+
Fix from $2,300 2022-12-22
Jsonwebtoken HIGH 7.6
CVE-2022-23540

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass …

Fix: after 8.5.1
Fix from $1,950 2022-12-22
Jsonwebtoken MEDIUM 6.3
CVE-2022-23541

jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly imp…

Fix: after 8.5.1
Fix from $1,600 2022-12-22
Harmonyos MEDIUM 5.3
CVE-2022-46313

The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of the smartpho…

Fix: 3.0.0+
Fix from $1,600 2022-12-20