Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Harmonyos CRITICAL 9.8
CVE-2022-46316

A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confid…

Fix: 2.1+
Fix from $2,300 2022-12-20
Harmonyos MEDIUM 5.5
CVE-2022-41590

Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypassed. Successful exploitation …

No fix yet
Fix from $1,600 2022-12-20
Bm78 Firmware MEDIUM 5.4
CVE-2022-46400

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in le…

No fix yet
Fix from $1,600 2022-12-19
Passwordstate HIGH 7.5
CVE-2022-3875

A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affect…

No fix yet
Fix from $1,950 2022-12-19
Bigfix Platform MEDIUM 6.5
CVE-2022-42453

There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of the script is the logged in u…

Fix: 9.5.21 / 10.0.8+
Fix from $1,600 2022-12-19
Rax30 Firmware HIGH 8.8
CVE-2022-47209

A support user exists on the device and appears to be a backdoor for Technical Support staff. The default password for this account is “support” and …

Fix: 1.0.9.90+
Fix from $1,950 2022-12-16
Serv U HIGH 7.5
CVE-2021-35252

Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an…

Fix: 15.3.2+
Fix from $1,950 2022-12-16
Fp Newsletter CRITICAL 9.1
CVE-2022-47408

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.…

Fix: 1.1.1 / 2.1.2+
Fix from $2,300 2022-12-14
TYPO3 MEDIUM 6.5
CVE-2022-23501

TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 TYPO3 is vulnerabl…

Fix: 8.7.49 / 9.5.38+
Fix from $1,600 2022-12-14
Tms300 Cs Firmware CRITICAL 9.1
CVE-2022-2757

Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing and modifying t…

Mitigation only
Fix from $2,300 2022-12-13
Apq8009 Firmware HIGH 7.5
CVE-2022-25685

Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,…

Mitigation only
Fix from $1,950 2022-12-13
Passport Wsfed Saml2 HIGH 7.5
CVE-2022-23505

Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker…

Fix: after 4.6.2
Fix from $1,950 2022-12-13
Gatemanager HIGH 7.8
CVE-2022-2752

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. …

Fix: after 9.7
Fix from $1,950 2022-12-09
Jetbrains Gateway HIGH 8.8
CVE-2022-46829

In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.

Fix: 2022.3+
Fix from $1,950 2022-12-08
Openharmony MEDIUM 5.3
CVE-2022-45877

OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authenticati…

Fix: after 3.1.4
Fix from $1,600 2022-12-08
Openharmony MEDIUM 5.5
CVE-2022-45118

OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the p…

Fix: after 3.1.4
Fix from $1,600 2022-12-08
Exynos Firmware MEDIUM 6.5
CVE-2022-39901

Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between U…

Mitigation only
Fix from $1,600 2022-12-08
Wcr 300 Firmware HIGH 8.8
CVE-2022-40966

Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the de…

Fix: after 2.96
Fix from $1,950 2022-12-07
Bingo\!cms CRITICAL 9.8
CVE-2022-42458

Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attack…

Fix: after 1.7.4.1
Fix from $2,300 2022-12-07
Udr Ja1604 Firmware HIGH 8.8
CVE-2022-44620

Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authentica…

Fix: 71x10.1.107114.43a+
Fix from $1,950 2022-12-07
Fortiproxy CRITICAL 9.8
CVE-2022-35843

An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 thr…

Fix: after 7.0.7
Fix from $2,300 2022-12-06
Mobaxterm HIGH 8.1
CVE-2022-38336

An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentica…

Fix: 22.2+
Fix from $1,950 2022-12-06
Bodyguard 999 603 Firmware MEDIUM 5.3
CVE-2022-43557

The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical acc…

Mitigation only
Fix from $1,600 2022-12-05
Megarac Sp X CRITICAL 9.8
CVE-2022-40242

MegaRAC Default Credentials Vulnerability

Mitigation only
Fix from $2,300 2022-12-05
Megarac Sp X CRITICAL 9.8
CVE-2022-40259

MegaRAC Default Credentials Vulnerability

No fix yet
Fix from $2,300 2022-12-05
Veeam Backup For Google Cloud CRITICAL 9.8
CVE-2022-43549

Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

Mitigation only
Fix from $2,300 2022-12-05
WordPress MEDIUM 5.3
CVE-2022-43504

Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of th…

Fix: 3.7.40 / 3.8.40+
Fix from $1,600 2022-12-05
Access Appliance HIGH 8.8
CVE-2022-46411

An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after insta…

Fix: after 8.0.100
Fix from $1,950 2022-12-04
Authentik CRITICAL 9.8
CVE-2022-46145

authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential a…

Fix: 2022.10.2 / 2022.11.2+
Fix from $2,300 2022-12-02
Websphere Automation For Ibm Cloud Pak For Watson Aiops MEDIUM 6.5
CVE-2022-43900

IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbo…

Fix: 1.4.3+
Fix from $1,600 2022-12-01