Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Keycloak HIGH 7.5
CVE-2021-3632

A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered…

Fix: 7.4.9 / 15.1.0+
Fix from $1,950 2022-08-26
Ceph Storage MEDIUM 6.5
CVE-2021-3979

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo…

Patch available
Fix from $1,600 2022-08-25
Samba HIGH 8.8
CVE-2022-2031

A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them t…

Fix: 4.14.14 / 4.15.9+
Fix from $1,950 2022-08-25
Candlepin MEDIUM 5.5
CVE-2021-4142

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (sim…

Fix: after 4.1.8-1
Fix from $1,600 2022-08-24
Video Gallery CRITICAL 9.8
CVE-2022-35726

Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.

Fix: 1.3.5+
Fix from $2,300 2022-08-23
Keycloak MEDIUM 6.8
CVE-2021-3827

A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at…

Fix: 18.0.0+
Fix from $1,600 2022-08-23
Tv Ip572pi Firmware HIGH 7.2
CVE-2022-35203

An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

Mitigation only
Fix from $1,950 2022-08-23
Contensis CRITICAL 9.8
CVE-2022-34919

The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted …

Fix: 15.2.1.79+
Fix from $2,300 2022-08-23
Avideo HIGH 8.8
CVE-2022-32282

An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' passw…

No fix yet
Fix from $1,950 2022-08-22
Wp Oauth Server CRITICAL 9.8
CVE-2022-34149

Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.

Fix: after 3.0.4
Fix from $2,300 2022-08-22
Edge Insights For Industrial CRITICAL 9.8
CVE-2022-22730

Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially e…

Fix: 2.6.1+
Fix from $2,300 2022-08-18
Contract Managment System HIGH 7.5
CVE-2022-35198

Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.

No fix yet
Fix from $1,950 2022-08-18
Edgeaggregator CRITICAL 9.8
CVE-2022-2336

Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and passwor…

Mitigation only
Fix from $2,300 2022-08-17
Portbloque S Firmware CRITICAL 9.8
CVE-2022-2662

Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access t…

Mitigation only
Fix from $2,300 2022-08-16
Gateway HIGH 8.8
CVE-2022-38368

An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an aut…

Fix: 6.6.5712 / 6.7.1376+
Fix from $1,950 2022-08-15
Go Rt Ac750 Firmware HIGH 7.5
CVE-2022-36524

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

Mitigation only
Fix from $1,950 2022-08-15
Yugabytedb CRITICAL 9.8
CVE-2022-37397

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or una…

Mitigation only
Fix from $2,300 2022-08-12
Linux Kernel MEDIUM 6.7
CVE-2022-2503

Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trus…

Fix: 5.19+
Fix from $1,600 2022-08-12
Ktor MEDIUM 6.5
CVE-2022-38180

In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

Fix: 2.1.0+
Fix from $1,600 2022-08-12
Company Website Cms CRITICAL 9.8
CVE-2022-2765

A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown f…

No fix yet
Fix from $2,300 2022-08-11
Msnswitch Firmware CRITICAL 9.8
CVE-2022-32429EPSS 76%

An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 al…

No fix yet
Fix from $2,300 2022-08-10
Chengming 3980 Firmware MEDIUM 6.8
CVE-2022-29083

Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could poten…

Fix: 1.7.0 / 1.11.0+
Fix from $1,600 2022-08-09
Android HIGH 7.1
CVE-2022-33732

Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unpro…

Mitigation only
Fix from $1,950 2022-08-05
Activedemand MEDIUM 5.3
CVE-2022-36296

Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.

Fix: after 0.2.27
Fix from $1,600 2022-08-05
Private Cloud Management Platform CRITICAL 9.8
CVE-2022-2664

A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/a…

Mitigation only
Fix from $2,300 2022-08-05
Raneto HIGH 7.5
CVE-2022-35142

An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.

Fix: 0.17.1+
Fix from $1,950 2022-08-04
Bookwyrm CRITICAL 9.8
CVE-2022-35925

BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brut…

Fix: 0.4.5+
Fix from $2,300 2022-08-02
Velociraptor MEDIUM 5.4
CVE-2022-35629

Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own cl…

Fix: 0.6.5-2+
Fix from $1,600 2022-07-29
Mb.miniaudioplayer HIGH 7.5
CVE-2016-0796

WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security …

Fix: after 1.7.6
Fix from $1,950 2022-07-28
Debian Linux MEDIUM 6.5
CVE-2022-2553

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes …

Fix: after 1.0
Fix from $1,600 2022-07-28