Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Iphone Os MEDIUM 5.3
CVE-2022-32928

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network po…

Fix: 9.0 / 13.0+
Fix from $1,600 2022-11-01
Octopus Server CRITICAL 9.8
CVE-2022-2572

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a dis…

Fix: 2022.1.3264 / 2022.2.8277+
Fix from $2,300 2022-11-01
Hubshare HIGH 7.5
CVE-2022-39018

Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a know…

Fix: 3.3.11.3+
Fix from $1,950 2022-10-31
Hubshare HIGH 7.5
CVE-2022-39019

Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the a…

Fix: 3.3.11.3+
Fix from $1,950 2022-10-31
Tnc 640 Programming Station CRITICAL 9.8
CVE-2022-41648

The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machin…

Mitigation only
Fix from $2,300 2022-10-28
Datahub CRITICAL 9.8
CVE-2022-39366

DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not veri…

Fix: 0.8.45+
Fix from $2,300 2022-10-28
Aruba Edgeconnect Enterprise Orchestrator CRITICAL 9.8
CVE-2022-37913

Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to …

Fix: 8.10.23.40009 / 9.0.7.40108+
Fix from $2,300 2022-10-28
Aruba Edgeconnect Enterprise Orchestrator CRITICAL 9.8
CVE-2022-37914

Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to …

Fix: 8.10.23.40009 / 9.0.7.40108+
Fix from $2,300 2022-10-28
Factorytalk Alarms And Events HIGH 7.5
CVE-2022-38744

An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, caus…

Mitigation only
Fix from $1,950 2022-10-27
Kardia MEDIUM 6.1
CVE-2022-40703

CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthentica…

Fix: after 5.17.1-754993421
Fix from $1,600 2022-10-26
Patreon CRITICAL 9.8
CVE-2022-39355

Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabled, an improper authenticatio…

Fix: 2022-10-26+
Fix from $2,300 2022-10-26
Metabase MEDIUM 6.5
CVE-2022-39360

Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) us…

Fix: 0.41.9 / 0.42.6+
Fix from $1,600 2022-10-26
Sanitization Management System CRITICAL 9.8
CVE-2022-3674

A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an …

Mitigation only
Fix from $2,300 2022-10-26
Powerstoreos CRITICAL 9.8
CVE-2022-26870

Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vul…

Patch available
Fix from $2,300 2022-10-21
Siveillance Video Mobile Server CRITICAL 9.8
CVE-2022-43400

A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected…

Fix: 22.2a+
Fix from $2,300 2022-10-21
11n Firmware CRITICAL 9.8
CVE-2022-42233EPSS 43%

Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

No fix yet
Fix from $2,300 2022-10-20
Shinken Monitoring CRITICAL 9.8
CVE-2022-37298

Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safep…

Patch available
Fix from $2,300 2022-10-20
Bifrost HIGH 8.8
CVE-2022-39267

Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environ…

Fix: after 1.8.6
Fix from $1,950 2022-10-19
Fedora MEDIUM 5.3
CVE-2022-21618

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affec…

Fix: after 11.70.2
Fix from $1,600 2022-10-18
Fortiproxy CRITICAL 9.8
CVE-2022-40684 KEVEPSS 100%

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiP…

Fix: 7.0.7 / 7.2.2+
Fix from $2,300 2022-10-18
Wire Server HIGH 8.1
CVE-2022-31122

Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If…

Fix: 2022-07-12+
Fix from $1,950 2022-10-18
Junos MEDIUM 6.5
CVE-2022-22237

An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an imp…

Mitigation only
Fix from $1,600 2022-10-18
GitLab HIGH 7.4
CVE-2022-2533

An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting from 15.2 before 15.2.4, all v…

Fix: 15.1.6 / 15.2.4+
Fix from $1,950 2022-10-17
Reversewall Mds CRITICAL 9.8
CVE-2022-23769

Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerabilit…

Fix: 3.8_a008+
Fix from $2,300 2022-10-17
Tp50 Firmware CRITICAL 9.1
CVE-2022-41436

An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.ht…

No fix yet
Fix from $2,300 2022-10-14
Harmonyos CRITICAL 9.8
CVE-2022-38982

The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.

No fix yet
Fix from $2,300 2022-10-14
Openharmony HIGH 7.8
CVE-2022-42488

OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious applicat…

Fix: 3.1.2+
Fix from $1,950 2022-10-14
Openharmony HIGH 8.8
CVE-2022-42463

OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication su…

Fix: after 3.1.2
Fix from $1,950 2022-10-14
Iot Platform HIGH 8.8
CVE-2022-35135

Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.

No fix yet
Fix from $1,950 2022-10-13
Debian Linux HIGH 7.5
CVE-2021-36369

An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH …

Fix: after 2020.81
Fix from $1,950 2022-10-12