Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ipc Hx1xxx Firmware CRITICAL 9.8
CVE-2021-33046

Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deploy…

Fix: after 2021-7
Fix from $2,300 2022-01-13
Fedora MEDIUM 5.3
CVE-2022-23134 KEVEPSS 85%

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. M…

Fix: after 5.4.8
Fix from $1,600 2022-01-13
Guacamole HIGH 8.8
CVE-2021-43999

Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allo…

Mitigation only
Fix from $1,950 2022-01-11
Lens CRITICAL 9.6
CVE-2021-44458

Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connectio…

Fix: after 5.2.6
Fix from $2,300 2022-01-10
S Assistant MEDIUM 5.3
CVE-2022-22289

Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.

Fix: 7.5+
Fix from $1,600 2022-01-10
Internet MEDIUM 5.5
CVE-2022-22284

Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

Fix: 16.0.2.19+
Fix from $1,600 2022-01-10
Command Center CRITICAL 9.8
CVE-2021-45389

A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the authentication process, thus co…

Mitigation only
Fix from $2,300 2022-01-04
Network Computer Terminal Protection System Firmware CRITICAL 9.0
CVE-2021-45917

The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated attacker of an agent computer…

Fix: 7.20.0401+
Fix from $2,300 2022-01-03
Tew 827dru Firmware MEDIUM 6.8
CVE-2021-20161

Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious actor with physical access to…

Mitigation only
Fix from $1,600 2021-12-30
Rax43 Firmware MEDIUM 6.8
CVE-2021-20168

Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physical access to the device is ab…

Mitigation only
Fix from $1,600 2021-12-30
R6700 Firmware MEDIUM 6.8
CVE-2021-23147

Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor with physical access to the de…

Mitigation only
Fix from $1,600 2021-12-30
Glewlwyd HIGH 8.8
CVE-2021-45379

Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its p…

Fix: 2.6.1+
Fix from $1,950 2021-12-30
Qfile HIGH 7.5
CVE-2021-38688

An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromi…

Fix: 3.0.0.1105+
Fix from $1,950 2021-12-29
Authguard CRITICAL 9.8
CVE-2021-45890

basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.

Fix: 0.9.0+
Fix from $2,300 2021-12-27
Eufy Homebase 2 Firmware CRITICAL 9.8
CVE-2021-21952

An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase …

No fix yet
Fix from $2,300 2021-12-22
Ic Module Cma HIGH 8.1
CVE-2021-21902

An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A proper…

No fix yet
Fix from $1,950 2021-12-22
Amegaview CRITICAL 9.8
CVE-2021-27451

Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to t…

Fix: after 3.0
Fix from $2,300 2021-12-21
Powerscale Onefs HIGH 7.5
CVE-2021-36350

Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authentication factors. A remote un…

Fix: 9.3.1.0+
Fix from $1,950 2021-12-21
Manageengine Pam360 CRITICAL 9.8
CVE-2021-44525

Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authenti…

Mitigation only
Fix from $2,300 2021-12-20
Manageengine Servicedesk Plus Msp CRITICAL 9.8
CVE-2021-44675EPSS 6%

Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which…

Fix: after 10.5
Fix from $2,300 2021-12-20
Manageengine Access Manager Plus CRITICAL 9.8
CVE-2021-44676

Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects o…

Mitigation only
Fix from $2,300 2021-12-20
Gim HIGH 7.5
CVE-2021-40851

TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulner…

Mitigation only
Fix from $1,950 2021-12-17
Elabftw HIGH 8.8
CVE-2021-43833

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated …

Fix: 4.2.0+
Fix from $1,950 2021-12-16
Elabftw CRITICAL 9.8
CVE-2021-43834

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to aut…

Fix: 4.2.0+
Fix from $2,300 2021-12-16
Welch Allyn Connex Cardio CRITICAL 9.8
CVE-2021-43935

The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the applicatio…

Fix: after 7.0.0
Fix from $2,300 2021-12-15
Registrationmagic HIGH 8.1
CVE-2021-4073EPSS 7%

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew …

Fix: after 5.0.1.7
Fix from $1,950 2021-12-14
Glfusion MEDIUM 5.3
CVE-2021-44937

glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox …

No fix yet
Fix from $1,600 2021-12-14
Sipass Integrated CRITICAL 9.8
CVE-2021-44524

A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All v…

Fix: after 1.6.284.0
Fix from $2,300 2021-12-14
Spectrum Copy Data Management HIGH 7.5
CVE-2021-39064

IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the S…

Fix: after 2.2.13
Fix from $1,950 2021-12-13
Manageengine Opmanager CRITICAL 9.8
CVE-2021-44514EPSS 5%

OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

Mitigation only
Fix from $2,300 2021-12-09