Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
389 Directory Server MEDIUM 6.5
CVE-2022-0996

A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.

No fix yet
Fix from $1,600 2022-03-23
Epolicy Orchestrator MEDIUM 5.3
CVE-2022-0862

A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow…

Fix: 5.10.0+
Fix from $1,600 2022-03-23
Traffic Server HIGH 8.1
CVE-2021-44759

Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This…

Fix: after 8.1.0
Fix from $1,950 2022-03-23
F35 Firmware MEDIUM 6.8
CVE-2021-46390

An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (Do…

No fix yet
Fix from $1,600 2022-03-21
Openvpn CRITICAL 9.8
CVE-2022-0547

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of def…

Fix: 2.4.12 / 2.5.6+
Fix from $2,300 2022-03-18
Veeam Backup \& Replication HIGH 8.8
CVE-2022-26504

Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (…

Fix: 10.0.1.4854 / 11.0.1.1261+
Fix from $1,950 2022-03-17
Maccms CRITICAL 9.8
CVE-2021-45786

In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

No fix yet
Fix from $2,300 2022-03-16
Volto HIGH 7.5
CVE-2022-24740

Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have thei…

Fix: after 14.10.0
Fix from $1,950 2022-03-14
Centum Cs 3000 Firmware HIGH 8.8
CVE-2022-22729

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be by…

Mitigation only
Fix from $1,950 2022-03-11
Account MEDIUM 5.5
CVE-2022-25825

Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.

Fix: 13.1.0.1+
Fix from $1,600 2022-03-10
Quickaccess HIGH 7.8
CVE-2022-24286

Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process comm…

Fix: 2.01.3030 / 3.00.3038+
Fix from $1,950 2022-03-10
Care Center HIGH 7.8
CVE-2022-24285

Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process communicates with a service of syst…

Fix: 4.00.3042+
Fix from $1,950 2022-03-10
Yzmcms CRITICAL 9.1
CVE-2022-23383

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessar…

Mitigation only
Fix from $2,300 2022-03-10
Update Manager HIGH 7.8
CVE-2021-40376

otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A re…

No fix yet
Fix from $1,950 2022-03-10
Shopware HIGH 7.5
CVE-2022-24748

Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions prior to 6.4.8.2 it is possibl…

Fix: 6.4.8.2+
Fix from $1,950 2022-03-09
Smt Series 1015 Ups Firmware CRITICAL 9.1
CVE-2022-0715EPSS 6%

A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leak…

Fix: after 04.5
Fix from $2,300 2022-03-09
Evmos HIGH 7.4
CVE-2022-24738

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed fund…

Fix: 2.0.1+
Fix from $1,950 2022-03-07
Android HIGH 7.8
CVE-2022-23729

When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

Fix: 11.0+
Fix from $1,950 2022-03-04
Debian Linux CRITICAL 9.8
CVE-2022-0730

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

No fix yet
Fix from $2,300 2022-03-03
Linux Kernel HIGH 7.8
CVE-2022-0492 KEVEPSS 6%

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circum…

Fix: 4.9.301 / 4.14.266+
Fix from $1,950 2022-03-03
1734 Aentr Point I\/o Dual Port Network Adaptor Series B Firmware MEDIUM 5.3
CVE-2020-14504

The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can sen…

Fix: after 5.017
Fix from $1,600 2022-02-24
Istio HIGH 7.5
CVE-2022-23635

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a re…

Fix: 1.11.7 / 1.12.4+
Fix from $1,950 2022-02-22
Capsule Proxy HIGH 8.8
CVE-2022-23652

capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a prope…

Fix: 0.2.1+
Fix from $1,950 2022-02-22
Wiki.js MEDIUM 6.5
CVE-2022-23654

Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page o…

Fix: 2.5.276+
Fix from $1,600 2022-02-22
Track It\! CRITICAL 9.8
CVE-2022-24047

This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re…

Mitigation only
Fix from $2,300 2022-02-18
Mimosa Management Platform CRITICAL 9.8
CVE-2022-21196

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does…

Fix: 1.0.3 / 2.5.4.1+
Fix from $2,300 2022-02-18
Debian Linux MEDIUM 5.9
CVE-2016-2124

A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w…

Patch available
Fix from $1,600 2022-02-18
Debian Linux HIGH 7.2
CVE-2020-25719

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b…

Patch available
Fix from $1,950 2022-02-18
Cobalt Strike HIGH 7.5
CVE-2022-23317

CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by spec…

Fix: 4.5+
Fix from $1,950 2022-02-15
Access Management CRITICAL 9.8
CVE-2021-4201

Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack s…

Patch available
Fix from $2,300 2022-02-14