Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Apex One CRITICAL 9.8
CVE-2022-40144

A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by…

Patch available
Fix from $2,300 2022-09-19
Wifi Mouse Server CRITICAL 9.8
CVE-2022-3218EPSS 73%

Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which…

Patch available
Fix from $2,300 2022-09-19
Emui CRITICAL 9.8
CVE-2022-39009

The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WL…

No fix yet
Fix from $2,300 2022-09-16
Hoteldruid CRITICAL 9.8
CVE-2021-42949EPSS 6%

The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to by…

Mitigation only
Fix from $2,300 2022-09-16
Csr8811 Firmware HIGH 7.8
CVE-2022-25652

Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking

Mitigation only
Fix from $1,950 2022-09-16
Twisted Vnc Authentication Proxy CRITICAL 9.8
CVE-2022-36436

OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability tha…

Fix: 1.2.0+
Fix from $2,300 2022-09-14
Wn531g3 Firmware HIGH 8.8
CVE-2022-40622

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens.…

No fix yet
Fix from $1,950 2022-09-13
Onedev CRITICAL 9.8
CVE-2022-39205

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a On…

Fix: 7.3.0+
Fix from $2,300 2022-09-13
TYPO3 MEDIUM 5.4
CVE-2022-36106

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a pass…

Fix: after 11.5.15
Fix from $1,600 2022-09-13
Access Control HIGH 7.5
CVE-2022-39801

SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefi…

Mitigation only
Fix from $1,950 2022-09-13
Openharmony MEDIUM 5.5
CVE-2022-38081

OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take adv…

Fix: after 3.1.2
Fix from $1,600 2022-09-09
Openharmony HIGH 8.8
CVE-2022-38700

OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera s…

Mitigation only
Fix from $1,950 2022-09-09
Openharmony MEDIUM 5.5
CVE-2022-38064

OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive informa…

Fix: after 3.1.2
Fix from $1,600 2022-09-09
Xwiki HIGH 7.5
CVE-2022-36092

XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that wou…

Fix: 13.10.4 / 14.2+
Fix from $1,950 2022-09-08
Xwiki HIGH 7.1
CVE-2022-36093

XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart…

Fix: 13.10.5 / 14.3+
Fix from $1,950 2022-09-08
Ihatetobudget CRITICAL 9.8
CVE-2022-37163

Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via bru…

Mitigation only
Fix from $2,300 2022-09-08
Ontrack CRITICAL 9.8
CVE-2022-37164

Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force a…

Mitigation only
Fix from $2,300 2022-09-08
Rv110w Firmware CRITICAL 9.8
CVE-2022-20923

A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an…

Mitigation only
Fix from $2,300 2022-09-08
Cs Qr20 Firmware MEDIUM 6.8
CVE-2022-38399

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an a…

Mitigation only
Fix from $1,600 2022-09-08
Rubygems HIGH 8.8
CVE-2022-36073

RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org acco…

Fix: 2022-08-31+
Fix from $1,950 2022-09-07
Phpfusion HIGH 8.8
CVE-2022-3152

Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.

Fix: 9.10.20+
Fix from $1,950 2022-09-07
Alienware M15 R6 Firmware HIGH 7.8
CVE-2022-26858

Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerabil…

Fix: 1.8.0 / 1.8.2+
Fix from $1,950 2022-09-06
Indy Node HIGH 8.8
CVE-2022-31020

Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and prior, the `pool-upgrade` re…

Fix: after 1.12.4
Fix from $1,950 2022-09-06
Sftpgo HIGH 8.1
CVE-2022-36071

SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based…

Fix: 2.3.4+
Fix from $1,950 2022-09-02
Powerprotect Cyber Recovery CRITICAL 9.1
CVE-2022-34372

Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may pote…

Fix: 19.11.0.2+
Fix from $2,300 2022-09-01
Cloudlink CRITICAL 9.8
CVE-2022-34379

Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active d…

Fix: 7.1.3+
Fix from $2,300 2022-09-01
Cloudlink HIGH 8.2
CVE-2022-34380

Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged lo…

Fix: 7.1.4+
Fix from $1,950 2022-09-01
Tew733gr Firmware CRITICAL 9.8
CVE-2022-38556

Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

No fix yet
Fix from $2,300 2022-08-28
Dir 845l Firmware CRITICAL 9.8
CVE-2022-38557

D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

Fix: after 1.0.3
Fix from $2,300 2022-08-28
Dir 845l Firmware CRITICAL 9.8
CVE-2022-36755

D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

Fix: after 1.0.3
Fix from $2,300 2022-08-28