Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ace1000 Firmware CRITICAL 9.8
CVE-2022-30270

The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote ma…

Mitigation only
Fix from $2,300 2022-07-26
Manageengine Supportcenter Plus CRITICAL 9.8
CVE-2022-36412EPSS 5%

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be exe…

Mitigation only
Fix from $2,300 2022-07-26
Wifi Repeater Firmware MEDIUM 5.7
CVE-2022-34575

An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via acc…

No fix yet
Fix from $1,600 2022-07-25
Wp Oauth2 Server CRITICAL 9.8
CVE-2022-34839

Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.

Fix: after 1.0.1
Fix from $2,300 2022-07-22
Tovy HIGH 7.5
CVE-2022-31164

Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including p…

Fix: 0.7.51+
Fix from $1,950 2022-07-22
Custom Product Tabs For Woocommerce MEDIUM 5.3
CVE-2022-28666

Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-togg…

Fix: after 1.7.7
Fix from $1,600 2022-07-21
Bamboo CRITICAL 9.8
CVE-2022-26136EPSS 5%

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-07-20
Mv720 Firmware CRITICAL 9.8
CVE-2022-2141

SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.

Mitigation only
Fix from $2,300 2022-07-20
Megapix Firmware HIGH 7.5
CVE-2022-34535

Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.

Mitigation only
Fix from $1,950 2022-07-19
P5e Gnss Firmware CRITICAL 9.8
CVE-2022-30623

The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true…

No fix yet
Fix from $2,300 2022-07-18
P5e Gnss Firmware HIGH 7.5
CVE-2022-30624

Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.

Mitigation only
Fix from $1,950 2022-07-18
Debian Linux CRITICAL 9.8
CVE-2021-40874

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (…

Patch available
Fix from $2,300 2022-07-18
Debian Linux HIGH 8.8
CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver …

Fix: 2.4.0+
Fix from $1,950 2022-07-17
Oauth Single Sign On MEDIUM 5.3
CVE-2022-2133

The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to l…

Fix: 6.22.6+
Fix from $1,600 2022-07-17
Job Portal Script CRITICAL 9.8
CVE-2017-20133

A vulnerability, which was classified as critical, was found in Itech Job Portal Script 9.13. This affects an unknown part of the file /admin. The ma…

Mitigation only
Fix from $2,300 2022-07-16
Android HIGH 7.8
CVE-2022-30755

Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the…

Mitigation only
Fix from $1,950 2022-07-12
Opcenter Quality HIGH 7.5
CVE-2022-33736

A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624), Opcenter Quality V13.2 (All versions < V13.2.20220624)…

Fix: 13.1.20220624 / 13.2.20220624+
Fix from $1,950 2022-07-12
C520 Firmware CRITICAL 9.8
CVE-2022-2302

Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a…

Fix: 01.08.01.3021+
Fix from $2,300 2022-07-11
Google Login MEDIUM 6.5
CVE-2015-5298

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are suppo…

Mitigation only
Fix from $1,600 2022-07-07
Roxy Wi CRITICAL 9.8
CVE-2022-31125EPSS 20%

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-06
Nacos HIGH 8.8
CVE-2021-43116EPSS 7%

An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and t…

Fix: after 2.0.3
Fix from $1,950 2022-07-05
Garoon MEDIUM 5.3
CVE-2022-28713

Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain some data of Facility Informat…

Fix: after 5.5.1
Fix from $1,600 2022-07-04
Pingid Integration For Mac Login HIGH 7.5
CVE-2021-41995

A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.

Fix: 1.1+
Fix from $1,950 2022-06-30
Rme1 Firmware CRITICAL 9.8
CVE-2022-2197

By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and p…

Fix: after 2.1.6
Fix from $2,300 2022-06-30
Ahb7008t Mh V2 Firmware CRITICAL 9.8
CVE-2021-41506

Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.N…

No fix yet
Fix from $2,300 2022-06-30
L2blocker HIGH 8.1
CVE-2022-33202

Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allow…

Fix: 4.8.6+
Fix from $1,950 2022-06-27
Meridian MEDIUM 5.3
CVE-2022-29578

Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information such as name, address, and dai…

Mitigation only
Fix from $1,600 2022-06-24
Ftp Server HIGH 7.5
CVE-2021-41638

The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by usi…

No fix yet
Fix from $1,950 2022-06-24
Sihas Sgw 300 Firmware CRITICAL 9.8
CVE-2021-26637

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized…

Mitigation only
Fix from $2,300 2022-06-23
S\&d Smarthome CRITICAL 9.8
CVE-2021-26638

Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attack…

Fix: after 3.2.48
Fix from $2,300 2022-06-23