Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Mlwr Ac1200r Firmware CRITICAL 9.8
CVE-2022-3465

A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipu…

No fix yet
Fix from $2,300 2022-10-12
Shiro CRITICAL 9.8
CVE-2022-40664

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

Fix: 1.10.0+
Fix from $2,300 2022-10-12
Zoneminder HIGH 7.5
CVE-2022-39289

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log conten…

Fix: 1.37.24+
Fix from $1,950 2022-10-07
Zoneminder MEDIUM 6.5
CVE-2022-39290EPSS 6%

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by mo…

Fix: 1.36.27 / 1.37.24+
Fix from $1,600 2022-10-07
Metasys Extended Application And Data Server MEDIUM 6.5
CVE-2022-21936

On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when usin…

Mitigation only
Fix from $1,600 2022-10-07
Nps CRITICAL 9.8
CVE-2022-40494

NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp…

Fix: after 0.26.10
Fix from $2,300 2022-10-06
Duo MEDIUM 6.8
CVE-2022-20662

A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass …

Fix: 2.0.0+
Fix from $1,600 2022-09-30
Matrix Rust Sdk HIGH 7.5
CVE-2022-39252

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to vers…

Fix: 0.6+
Fix from $1,950 2022-09-29
Matrix Nio MEDIUM 6.5
CVE-2022-39254

matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from…

Fix: 0.20+
Fix from $1,600 2022-09-29
Javascript Sdk HIGH 7.5
CVE-2022-39250

Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating wit…

Fix: 19.7.0+
Fix from $1,950 2022-09-29
Moodle MEDIUM 6.5
CVE-2021-40693

An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

Fix: 3.9.10 / 3.10.7+
Fix from $1,600 2022-09-29
Fedora MEDIUM 5.9
CVE-2022-39264

nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets,…

Fix: 0.10.2+
Fix from $1,600 2022-09-28
Software Development Kit HIGH 7.5
CVE-2022-39257

Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeser…

Fix: 0.23.19+
Fix from $1,950 2022-09-28
Next Auth HIGH 8.1
CVE-2022-39263

`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `ne…

Fix: 3.0.2+
Fix from $1,950 2022-09-28
Software Development Kit HIGH 7.5
CVE-2022-39255

Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeser…

Fix: 0.23.19+
Fix from $1,950 2022-09-28
Javascript Sdk HIGH 7.5
CVE-2022-39249

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver ca…

Fix: 19.7.0+
Fix from $1,950 2022-09-28
Javascript Sdk HIGH 7.5
CVE-2022-39251

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver ca…

Fix: 19.7.0+
Fix from $1,950 2022-09-28
Software Development Kit HIGH 7.5
CVE-2022-39248

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages…

Fix: 1.5.1+
Fix from $1,950 2022-09-28
Software Development Kit MEDIUM 5.3
CVE-2022-39246

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages…

Fix: 1.5.1+
Fix from $1,600 2022-09-28
Cpy Car Park Server HIGH 7.5
CVE-2022-22523

An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App whi…

Fix: 2.8.3 / 8.5.0.3+
Fix from $1,950 2022-09-28
Bifrost MEDIUM 6.5
CVE-2022-39219

Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vul…

Fix: 1.8.7+
Fix from $1,600 2022-09-26
Mist HIGH 7.8
CVE-2022-39245

Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable …

Fix: 0.9.5+
Fix from $1,950 2022-09-26
Oauth Client Single Sign On HIGH 7.5
CVE-2022-3119

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unau…

Fix: 3.0.4+
Fix from $1,950 2022-09-26
Rocket.chat HIGH 8.8
CVE-2022-35248

A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when te…

Fix: 4.7.5 / 4.8.2+
Fix from $1,950 2022-09-23
Rocket.chat MEDIUM 6.8
CVE-2022-30124

An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile dev…

Fix: 4.14.1.22788+
Fix from $1,600 2022-09-23
Vclient MEDIUM 5.9
CVE-2021-45035

Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could allow an attacker that has acce…

Mitigation only
Fix from $1,600 2022-09-23
Arvados HIGH 8.8
CVE-2022-39238

Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when using Portable Authentication Mod…

Fix: 2.4.3+
Fix from $1,950 2022-09-23
Maximo Asset Management HIGH 8.1
CVE-2022-40616

IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensitive information or perform tas…

Mitigation only
Fix from $1,950 2022-09-21
Ssd 600p Firmware MEDIUM 6.8
CVE-2021-33076

Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege…

Fix: 002c / 003c+
Fix from $1,600 2022-09-20
Linux Pam CRITICAL 9.8
CVE-2022-28321

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctl…

Fix: 1.5.2-6.1+
Fix from $2,300 2022-09-19