Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Samwin Agent CRITICAL 9.8
CVE-2013-10004

A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the functi…

No fix yet
Fix from $2,300 2022-05-24
Airfield Online HIGH 7.5
CVE-2021-4230

A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup ha…

Mitigation only
Fix from $1,950 2022-05-24
Opencast MEDIUM 5.4
CVE-2022-29237

Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass…

Fix: 10.14 / 11.7+
Fix from $1,600 2022-05-24
Vpn100 Firmware MEDIUM 6.5
CVE-2022-0910

A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions…

Fix: after 5.21
Fix from $1,600 2022-05-24
Argo Cd CRITICAL 10.0
CVE-2022-29165

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with versi…

Fix: 2.1.15 / 2.2.9+
Fix from $2,300 2022-05-20
Sooteway Wi Fi Range Extender HIGH 7.2
CVE-2021-30028

SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service,…

No fix yet
Fix from $1,950 2022-05-20
7kg8500 0aa00 0aa0 Firmware MEDIUM 5.3
CVE-2022-29883

A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the…

Fix: 3.00+
Fix from $1,600 2022-05-20
Online Sports Complex Booking System CRITICAL 9.8
CVE-2022-28106

Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request.

No fix yet
Fix from $2,300 2022-05-20
A1 Firmware MEDIUM 6.8
CVE-2021-42849

A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,600 2022-05-18
Dir 816l Firmware HIGH 7.5
CVE-2022-28955EPSS 40%

An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.

No fix yet
Fix from $1,950 2022-05-18
Sysaid CRITICAL 9.8
CVE-2022-22796

Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, t…

Fix: 21.1.30 / 21.4.45+
Fix from $2,300 2022-05-12
In Band Manageability HIGH 7.2
CVE-2021-0193

Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escala…

Fix: 2.13.0+
Fix from $1,950 2022-05-12
Wiki.js HIGH 7.2
CVE-2022-1681

Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

Fix: 2.5.281+
Fix from $1,950 2022-05-12
Smartbox 4 Lan Firmware CRITICAL 9.8
CVE-2019-12254

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsibl…

Mitigation only
Fix from $2,300 2022-05-06
Splunk HIGH 8.1
CVE-2021-26253

A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions be…

Fix: 8.1.6+
Fix from $1,950 2022-05-06
Metasys Application And Data Server HIGH 8.8
CVE-2022-21934

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server …

Fix: 10.1.5 / 11.0.2+
Fix from $1,950 2022-05-06
Video Station CRITICAL 9.8
CVE-2021-44056

An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attac…

Fix: 5.1.8 / 5.3.13+
Fix from $2,300 2022-05-05
Photo Station CRITICAL 9.8
CVE-2021-44057

An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attac…

Fix: 5.4.13 / 5.7.16+
Fix from $2,300 2022-05-05
Parse Server HIGH 7.5
CVE-2022-24901

Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making th…

Fix: 4.10.10 / 5.2.1+
Fix from $1,950 2022-05-04
Options HIGH 8.8
CVE-2022-0916

An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF at…

Fix: 9.60.87+
Fix from $1,950 2022-05-03
Pingfederate MEDIUM 6.5
CVE-2022-23722

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS aut…

Fix: 9.3.3 / 10.0.12+
Fix from $1,600 2022-05-02
Pingone Mfa Integration Kit HIGH 7.7
CVE-2022-23723

An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication …

Mitigation only
Fix from $1,950 2022-05-02
Pingid Integration For Windows Login MEDIUM 5.6
CVE-2021-41992

A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.

Fix: 2.7+
Fix from $1,600 2022-04-30
Fedora HIGH 7.5
CVE-2022-24882

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not prop…

Fix: 2.7.0+
Fix from $1,950 2022-04-26
Fedora CRITICAL 9.8
CVE-2022-24883

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might …

Fix: 2.7.0+
Fix from $2,300 2022-04-26
Veryfitpro HIGH 7.8
CVE-2021-36460

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication w…

Fix: after 3.3.7
Fix from $1,950 2022-04-25
Tos HIGH 8.1
CVE-2021-45841EPSS 8%

In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us…

No fix yet
Fix from $1,950 2022-04-25
Misp HIGH 7.5
CVE-2022-29534

An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: appli…

Fix: 2.4.158+
Fix from $1,950 2022-04-20
Jira Data Center CRITICAL 9.8
CVE-2022-0540EPSS 88%

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This a…

Fix: 4.13.8 / 4.13.18+
Fix from $2,300 2022-04-20
Qcp200w Firmware HIGH 7.5
CVE-2021-26627

Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attac…

Mitigation only
Fix from $1,950 2022-04-19