Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Zzcms HIGH 7.5
CVE-2021-45347

An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the coo…

No fix yet
Fix from $1,950 2022-02-14
Atheme CRITICAL 9.1
CVE-2022-24976

Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point…

Fix: 7.2.12+
Fix from $2,300 2022-02-14
C Gate Server HIGH 7.8
CVE-2021-22796

A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C…

Fix: after 2.11.7
Fix from $1,950 2022-02-11
Kazoo Server CRITICAL 9.8
CVE-2021-38679

An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers…

Fix: 4.11.22+
Fix from $2,300 2022-02-11
Aqt1000 Firmware HIGH 7.8
CVE-2021-30317

Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdrag…

Mitigation only
Fix from $1,950 2022-02-11
Gitea CRITICAL 9.8
CVE-2021-45331

An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for…

Fix: 1.5.0+
Fix from $2,300 2022-02-09
Xmpie Ustore HIGH 7.5
CVE-2022-23320

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrat…

No fix yet
Fix from $1,950 2022-02-07
Nas HIGH 8.8
CVE-2022-24551

A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could re…

Fix: 0.2+
Fix from $1,950 2022-02-06
Tessa CRITICAL 9.8
CVE-2022-22831EPSS 11%

An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.

No fix yet
Fix from $2,300 2022-02-06
Fleet MEDIUM 6.5
CVE-2022-23600

fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof SAML authentication with missi…

Fix: 4.9.1+
Fix from $1,600 2022-02-04
Eos CRITICAL 9.8
CVE-2021-28503

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, whi…

Fix: after 4.26.2
Fix from $2,300 2022-02-04
Seaconnect 370w Firmware CRITICAL 9.3
CVE-2021-21965

A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Speciall…

No fix yet
Fix from $2,300 2022-02-04
Voipmonitor CRITICAL 9.8
CVE-2022-24259

An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted re…

Fix: 24.96+
Fix from $2,300 2022-02-04
Rlc 410w Firmware MEDIUM 6.5
CVE-2021-40404

An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted H…

No fix yet
Fix from $1,600 2022-01-28
Integrated Dell Remote Access Controller 8 Firmware MEDIUM 5.3
CVE-2021-36346

Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker could potentially exploit this…

Fix: 2.82.82.82+
Fix from $1,600 2022-01-25
Ac2100 Firmware HIGH 8.8
CVE-2021-34865

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication i…

Fix: 1.0.1.80 / 1.1.0.84+
Fix from $1,950 2022-01-25
Debian Linux CRITICAL 9.1
CVE-2021-3850

Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.

Fix: after 5.20.21
Fix from $2,300 2022-01-25
Messaging Integration Services CRITICAL 9.8
CVE-2021-43394

Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm.…

Mitigation only
Fix from $2,300 2022-01-24
Teslamate CRITICAL 9.8
CVE-2022-23126

TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and in…

Fix: 1.25.1+
Fix from $2,300 2022-01-24
Agilia Partner Maintenance Software CRITICAL 9.8
CVE-2021-43355

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authenticat…

Fix: 3.0+
Fix from $2,300 2022-01-21
Agilia Connect Firmware CRITICAL 9.8
CVE-2021-23196

The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does n…

Fix: 3.0+
Fix from $2,300 2022-01-21
Cognos Controller CRITICAL 9.8
CVE-2020-4879

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of auth…

Mitigation only
Fix from $2,300 2022-01-21
Mc3224i Firmware CRITICAL 9.8
CVE-2021-44736

The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

Mitigation only
Fix from $2,300 2022-01-20
Onionshare MEDIUM 5.3
CVE-2022-21695

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In …

Fix: 2.5+
Fix from $1,600 2022-01-18
All In One Seo HIGH 8.8
CVE-2021-25036

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the …

Fix: 4.1.5.3+
Fix from $1,950 2022-01-17
Hd Md4x2 4k E Firmware CRITICAL 9.8
CVE-2022-23178EPSS 76%

An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthen…

No fix yet
Fix from $2,300 2022-01-15
R7000 Firmware HIGH 8.8
CVE-2021-34977

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers.…

Mitigation only
Fix from $1,950 2022-01-13
Commcell CRITICAL 9.8
CVE-2021-34993EPSS 5%

This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not r…

Mitigation only
Fix from $2,300 2022-01-13
Discourse HIGH 8.8
CVE-2022-21684

Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` all…

Fix: 2.7.13+
Fix from $1,950 2022-01-13
My Cloud Os HIGH 8.8
CVE-2022-22990

A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on…

Fix: 5.19.117+
Fix from $1,950 2022-01-13