Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ispy CRITICAL 9.8
CVE-2022-29775EPSS 61%

iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

No fix yet
Fix from $2,300 2022-06-21
Cerberus Dms CRITICAL 9.8
CVE-2022-33139

A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.1…

Mitigation only
Fix from $2,300 2022-06-21
Very Simple Contact Form HIGH 7.5
CVE-2022-1801

The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fiel…

Fix: 11.6+
Fix from $1,950 2022-06-20
Parse Server HIGH 7.5
CVE-2022-31083

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the cert…

Fix: 4.10.11 / 5.2.2+
Fix from $1,950 2022-06-17
Grafana HIGH 7.5
CVE-2022-32276

Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vu…

No fix yet
Fix from $1,950 2022-06-17
Utorrent HIGH 8.8
CVE-2018-25043

A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads t…

No fix yet
Fix from $1,950 2022-06-17
Voluson S8 Firmware HIGH 7.8
CVE-2020-36548

A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The mani…

Mitigation only
Fix from $1,950 2022-06-17
Ca Automic Automation CRITICAL 9.8
CVE-2022-33750

CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentia…

Mitigation only
Fix from $2,300 2022-06-16
Dir 850l Firmare HIGH 7.5
CVE-2018-18907

An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireles…

Fix: 1.21b07+
Fix from $1,950 2022-06-16
Ua .net Standard Stack HIGH 7.5
CVE-2022-29865

OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Windows 10 HIGH 7.5
CVE-2022-30150

Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2022-06-15
Metasys Application And Data Server HIGH 7.5
CVE-2022-21935

A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password cha…

Fix: 10.1.5+
Fix from $1,950 2022-06-15
Identity Services Engine CRITICAL 9.8
CVE-2022-20733

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentia…

No fix yet
Fix from $2,300 2022-06-15
Email Security Appliance CRITICAL 9.8
CVE-2022-20798

A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appli…

Fix: 13.0.0-277 / 13.6.2-090+
Fix from $2,300 2022-06-15
Sicam Gridedge Essential HIGH 7.2
CVE-2022-30229

A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated acce…

Fix: 2.6.6+
Fix from $1,950 2022-06-14
Aqt1000 Firmware HIGH 7.8
CVE-2021-35094

Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon…

Mitigation only
Fix from $1,950 2022-06-14
Flmg 10 Firmware MEDIUM 6.8
CVE-2022-22259

There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a contr…

Mitigation only
Fix from $1,600 2022-06-13
Smartthings HIGH 7.8
CVE-2022-30749

Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login act…

Fix: 1.7.85.25+
Fix from $1,950 2022-06-07
Platinum Mobile MEDIUM 6.5
CVE-2020-36528

A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken acce…

No fix yet
Fix from $1,600 2022-06-07
App CRITICAL 9.8
CVE-2020-36533

A vulnerability was found in Klapp App and classified as problematic. This issue affects some unknown processing of the JSON Web Token Handler. The m…

No fix yet
Fix from $2,300 2022-06-07
Wiser Smart Eer21000 Firmware HIGH 8.8
CVE-2022-30238

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a sessio…

Fix: after 4.5
Fix from $1,950 2022-06-02
Meeting Owl Pro Firmware HIGH 7.1
CVE-2022-31463

Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used.

Fix: 5.4.2.3+
Fix from $1,950 2022-06-02
Flower HIGH 8.6
CVE-2022-30034

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker coul…

Fix: 1.2.0+
Fix from $1,950 2022-06-02
Control Room Management Suite HIGH 7.5
CVE-2022-26975

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.

Fix: 3.14.1+
Fix from $1,950 2022-06-02
Chat Server CRITICAL 9.8
CVE-2022-31013

Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the acc…

Fix: 2.6.0+
Fix from $2,300 2022-05-31
Tidb HIGH 7.8
CVE-2022-31011

TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an at…

Mitigation only
Fix from $1,950 2022-05-31
Tvos MEDIUM 5.5
CVE-2022-26724

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Pho…

Fix: 15.5+
Fix from $1,600 2022-05-26
Curl HIGH 8.1
CVE-2022-22576

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections witho…

Fix: 7.83.0+
Fix from $1,950 2022-05-26
Idrac9 CRITICAL 9.8
CVE-2022-24422EPSS 58%

Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacke…

Fix: 5.10.10.00+
Fix from $2,300 2022-05-26
Supportassist Os Recovery MEDIUM 6.8
CVE-2022-26865

Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical acces…

Mitigation only
Fix from $1,600 2022-05-26