Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Abacus Erp 2018 HIGH 8.8
CVE-2022-1065

A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affec…

No fix yet
Fix from $1,950 2022-04-19
389 Ds Base MEDIUM 6.5
CVE-2021-3652

A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, a…

Fix: 2.0.7+
Fix from $1,600 2022-04-18
Django Mfa3 HIGH 8.8
CVE-2022-24857

django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by modifying the regular login vi…

Fix: 0.5.0+
Fix from $1,950 2022-04-15
Wireless Lan Controller 8.10.151.0 CRITICAL 10.0
CVE-2022-20695EPSS 20%

A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker t…

Mitigation only
Fix from $2,300 2022-04-15
B\/m9000 Vp CRITICAL 9.1
CVE-2022-26034

Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENT…

Mitigation only
Fix from $2,300 2022-04-15
Identity Manager CRITICAL 9.8
CVE-2022-22956EPSS 51%

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious …

Fix: 9.0+
Fix from $2,300 2022-04-13
Android MEDIUM 6.8
CVE-2022-25832

Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authent…

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 6.8
CVE-2022-26091

Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a fu…

Mitigation only
Fix from $1,600 2022-04-11
Emui HIGH 7.5
CVE-2021-46740

The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability ma…

No fix yet
Fix from $1,950 2022-04-11
Patient Portal MEDIUM 6.5
CVE-2022-1067

Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limi…

Mitigation only
Fix from $1,600 2022-04-11
Sap Information System HIGH 7.3
CVE-2022-1248

A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/…

No fix yet
Fix from $1,950 2022-04-06
C0 10dd1e D Firmware CRITICAL 9.8
CVE-2021-32984

All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the time Automation Direct CLICK…

Fix: 3.00+
Fix from $2,300 2022-04-04
C0 10dd1e D Firmware CRITICAL 9.8
CVE-2021-32980

Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional software programming connections…

Fix: 3.00+
Fix from $2,300 2022-04-04
Createwiki MEDIUM 5.3
CVE-2022-24813

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymous comments can be made using …

Fix: 2022-04-02+
Fix from $1,600 2022-04-04
Lvskihp Firmware HIGH 8.1
CVE-2022-28376

Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at …

Fix: after 2022-02-15
Fix from $1,950 2022-04-03
Fx5uc Firmware HIGH 8.1
CVE-2022-25155

Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubi…

Mitigation only
Fix from $1,950 2022-04-01
Fx5uc Firmware CRITICAL 9.1
CVE-2022-25157

Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubi…

Mitigation only
Fix from $2,300 2022-04-01
Groupware Core CRITICAL 9.8
CVE-2022-26562

An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user a…

No fix yet
Fix from $2,300 2022-04-01
Wyse Device Agent MEDIUM 6.7
CVE-2022-23156

Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could potentially exploit this vulner…

Fix: after 14.6.1.4
Fix from $1,600 2022-04-01
Ar8035 Firmware HIGH 7.8
CVE-2021-1950

Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdra…

Mitigation only
Fix from $1,950 2022-04-01
Webinar Manager MEDIUM 6.5
CVE-2021-45900

Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AU…

Fix: 3.6.3.0+
Fix from $1,600 2022-03-30
Cam Pan V2 Firmware CRITICAL 9.8
CVE-2019-9564

A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and control the devices. This issue…

Fix: 4.9.8.1002 / 4.36.8.32+
Fix from $2,300 2022-03-30
Joomla\! CRITICAL 9.8
CVE-2022-23795

An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which …

Fix: after 4.1.0
Fix from $2,300 2022-03-30
One Church Management System CRITICAL 9.8
CVE-2022-1084

A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown fun…

Mitigation only
Fix from $2,300 2022-03-29
Usg40 Firmware CRITICAL 9.8
CVE-2022-0342EPSS 84%

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware ve…

Fix: 4.71+
Fix from $2,300 2022-03-28
Impresscms MEDIUM 5.3
CVE-2021-26598EPSS 11%

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, ab…

Fix: 1.4.3+
Fix from $1,600 2022-03-28
Debian Linux HIGH 8.8
CVE-2022-1049

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to logi…

Fix: after 0.11.2
Fix from $1,950 2022-03-25
Nas101 Firmware HIGH 7.5
CVE-2021-26620

An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal importa…

Fix: 1.4.82+
Fix from $1,950 2022-03-25
Dir 816 Firmware CRITICAL 9.8
CVE-2021-31326

D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cg…

No fix yet
Fix from $2,300 2022-03-24
Linux Kernel HIGH 7.8
CVE-2021-4197

An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access t…

Fix: 4.14.276 / 4.19.238+
Fix from $1,950 2022-03-23