Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Orion Platform HIGH 8.8
CVE-2022-36960

SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Exporter Toolkit HIGH 8.8
CVE-2022-46146

Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml…

Fix: 0.7.2 / 0.8.2+
Fix from $1,950 2022-11-29
Vclient HIGH 7.4
CVE-2021-45036

Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id a…

Mitigation only
Fix from $1,950 2022-11-28
Saml CRITICAL 9.8
CVE-2022-41912

The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Asser…

Fix: 0.4.9+
Fix from $2,300 2022-11-28
Tm C3500 Firmware CRITICAL 9.1
CVE-2022-36133

The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.

Mitigation only
Fix from $2,300 2022-11-25
Maarch Rm MEDIUM 5.3
CVE-2022-37774

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a…

Fix: 2.8.6+
Fix from $1,600 2022-11-23
Nonstop Netbatch Plus HIGH 7.8
CVE-2022-37931

A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE…

Mitigation only
Fix from $1,950 2022-11-22
Lte3301 M209 Firmware CRITICAL 9.8
CVE-2022-40602

A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-…

Fix: 1.00+
Fix from $2,300 2022-11-22
Firepower Services Software For Asa HIGH 7.5
CVE-2022-20918

A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) F…

Fix: 7.0.5+
Fix from $1,950 2022-11-15
Ar9380 Firmware HIGH 7.5
CVE-2022-25667

Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking

Mitigation only
Fix from $1,950 2022-11-15
Concrete Cms MEDIUM 6.3
CVE-2022-43690

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_salt so that limited authenti…

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Newsmag CRITICAL 9.8
CVE-2022-3477

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does…

Fix: 3.5 / 5.2.2+
Fix from $2,300 2022-11-14
Powervm Hypervisor CRITICAL 9.8
CVE-2022-34331

After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VE…

Mitigation only
Fix from $2,300 2022-11-11
Nuc Kit Nuc5i3ryh Firmware HIGH 7.8
CVE-2022-37345

Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable e…

Patch available
Fix from $1,950 2022-11-11
Nuc Kit Nuc5i3myhe Firmware HIGH 7.8
CVE-2022-36370

Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to po…

Patch available
Fix from $1,950 2022-11-11
Active Management Technology Firmware HIGH 8.8
CVE-2022-29893

Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an aut…

Fix: 11.8.93 / 11.12.93+
Fix from $1,950 2022-11-11
Active Management Technology Firmware CRITICAL 9.8
CVE-2022-26845

Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an una…

Fix: 11.8.93 / 11.12.93+
Fix from $2,300 2022-11-11
Xmm 7560 Firmware HIGH 7.2
CVE-2022-27874

Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially e…

Mitigation only
Fix from $1,950 2022-11-11
Server Debug And Provisioning Tool HIGH 7.5
CVE-2022-26508

Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure …

Fix: 3.0.0+
Fix from $1,950 2022-11-11
Active Management Technology Firmware MEDIUM 6.7
CVE-2021-33159

Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a pri…

Fix: 11.8.93 / 11.12.93+
Fix from $1,600 2022-11-11
Nuc Kit Nuc8i7hnk Firmware MEDIUM 6.7
CVE-2022-21794

Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before versi…

Mitigation only
Fix from $1,600 2022-11-11
Agentflow HIGH 8.8
CVE-2022-39038

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user…

Mitigation only
Fix from $1,950 2022-11-10
Upsmon Pro CRITICAL 9.8
CVE-2022-38119

UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication…

Mitigation only
Fix from $2,300 2022-11-10
Lin Cms MEDIUM 6.6
CVE-2022-44244

An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.

No fix yet
Fix from $1,600 2022-11-09
Pass CRITICAL 9.8
CVE-2022-39892

Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.

Fix: 4.0.05.1+
Fix from $2,300 2022-11-09
Workspace One Assist CRITICAL 9.8
CVE-2022-31685

VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE As…

Fix: 22.10+
Fix from $2,300 2022-11-09
Workspace One Assist CRITICAL 9.8
CVE-2022-31686

VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace …

Fix: 22.10+
Fix from $2,300 2022-11-09
Gateway CRITICAL 9.8
CVE-2022-27510

Unauthorized access to Gateway user capabilities

Fix: 12.1-55.289 / 12.1-65.21+
Fix from $2,300 2022-11-08
Openid Connect HIGH 7.5
CVE-2022-39387

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has an OpenID provider configure…

Fix: 1.29.1+
Fix from $1,950 2022-11-04
Openharmony MEDIUM 6.5
CVE-2022-43451

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arb…

Fix: after 3.1.2
Fix from $1,600 2022-11-03